Policy
Coordinated Disclosure Policy
This is the disclosure policy for vulnerabilities found and published by PT Dewaguard Nusantara Siber's red team. It applies both when we report a bug we found in a third party's product, and to reports we receive about our own tools and infrastructure.
Scope
This policy covers vulnerabilities in third-party products discovered during authorized security research, and vulnerabilities in Dewaguard-owned software, services, and infrastructure. It does not cover social engineering, physical security testing, or denial-of-service testing against systems we do not own — get explicit written authorization before attempting any of that against us or anyone else.
How we disclose vulnerabilities we find
- We report the issue privately to the affected vendor, with enough detail to reproduce it.
- We request a CVE identifier and agree a coordinated publication date with the vendor where possible.
- We publish an advisory on this site once the fix is available, the agreed embargo lapses, or 90 days pass without a substantive vendor response — whichever comes first.
- Advisories are updated in place if new information changes severity, affected versions, or remediation guidance.
Reporting a vulnerability to us
If you believe you've found a security issue in something we operate, email us using the contact below. Please include the affected asset, steps to reproduce, and any proof-of-concept material. Do not include real customer data in your report.
What you can expect from us
- Acknowledgement of your report within 5 business days.
- An initial severity assessment and, where relevant, a CVE request within 30 days.
- Credit in the published advisory, unless you ask to remain anonymous.
- No legal action for good-faith research conducted under this policy.
Safe harbor
We will not pursue legal action against researchers who make a good-faith effort to follow this policy: avoid privacy violations, do not disrupt production systems, only interact with accounts and data you own or have explicit permission to test, and give us a reasonable window to remediate before any public disclosure.
Embargo & timing
Default embargo is 90 days from initial vendor notification, extendable by mutual agreement if a fix is actively in progress. We reserve the right to publish earlier if a vulnerability is independently discovered and disclosed elsewhere, or is being actively exploited.