Policy

Coordinated Disclosure Policy

This is the disclosure policy for vulnerabilities found and published by PT Dewaguard Nusantara Siber's red team. It applies both when we report a bug we found in a third party's product, and to reports we receive about our own tools and infrastructure.

Scope

This policy covers vulnerabilities in third-party products discovered during authorized security research, and vulnerabilities in Dewaguard-owned software, services, and infrastructure. It does not cover social engineering, physical security testing, or denial-of-service testing against systems we do not own — get explicit written authorization before attempting any of that against us or anyone else.

How we disclose vulnerabilities we find

  1. We report the issue privately to the affected vendor, with enough detail to reproduce it.
  2. We request a CVE identifier and agree a coordinated publication date with the vendor where possible.
  3. We publish an advisory on this site once the fix is available, the agreed embargo lapses, or 90 days pass without a substantive vendor response — whichever comes first.
  4. Advisories are updated in place if new information changes severity, affected versions, or remediation guidance.

Reporting a vulnerability to us

If you believe you've found a security issue in something we operate, email us using the contact below. Please include the affected asset, steps to reproduce, and any proof-of-concept material. Do not include real customer data in your report.

PGP key /pgp.txt
Response time acknowledgement within 5 business days

What you can expect from us

  • Acknowledgement of your report within 5 business days.
  • An initial severity assessment and, where relevant, a CVE request within 30 days.
  • Credit in the published advisory, unless you ask to remain anonymous.
  • No legal action for good-faith research conducted under this policy.

Safe harbor

We will not pursue legal action against researchers who make a good-faith effort to follow this policy: avoid privacy violations, do not disrupt production systems, only interact with accounts and data you own or have explicit permission to test, and give us a reasonable window to remediate before any public disclosure.

Embargo & timing

Default embargo is 90 days from initial vendor notification, extendable by mutual agreement if a fix is actively in progress. We reserve the right to publish earlier if a vulnerability is independently discovered and disclosed elsewhere, or is being actively exploited.