# DER Security Corp - Vulnerability Disclosure Contact # RFC 9116 (https://www.rfc-editor.org/rfc/rfc9116) # This file is also served at /.well-known/security.txt Contact: mailto:security@dersec.io Expires: 2027-05-28T00:00:00.000Z Preferred-Languages: en Canonical: https://dersec.io/.well-known/security.txt Canonical: https://www.dersec.io/.well-known/security.txt Policy: https://www.dersec.io/responsible-disclosure/ # If you have found a security issue in any DER Security Corp product line # (DERSec Sentry, DER Simulator, DERSec LabTest, DERSync CSIP Aggregator, # DERSec AHJ Registry, or any DERSec-hosted service), please contact us at # security@dersec.io. We commit to acknowledging your report within two # business days and providing a substantive response within ten business days. # Coordinated disclosure timelines and the rest of our policy are described # in our Penetration Testing and Responsible Disclosure Policy (POL-VM-001).