Security

Security Policy
& Disclosure

How to responsibly report security issues to DGRC Consulting — for this website and the systems we build and secure.

Reporting a vulnerability

If you've discovered a security vulnerability on this website or in a system DGRC Consulting manages, please report it responsibly. We take security seriously — it's our business.

Contact: dan@dgrc.consulting

Preferred: Email with as much detail as possible. Include steps to reproduce, the affected system/URL, and the impact you observed.

What we ask

  • Give us a reasonable time to respond and fix before disclosing publicly.
  • Don't access, modify, or exfiltrate data beyond what's needed to demonstrate the issue.
  • Don't perform destructive testing, denial-of-service, or social engineering against this site.
  • Don't test systems you don't own or have authorization for.

What we do

  • Acknowledge your report promptly.
  • Investigate and confirm the issue.
  • Remediate the vulnerability.
  • Credit you for responsible disclosure (if you'd like).

Out of scope

Third-party services and systems not operated by DGRC Consulting are out of scope for testing through this policy. This site is a static marketing site — it has no user accounts, payment processing, or sensitive data storage.

Have a security question?

Whether it's a report or a question about securing your own business, I'm glad to help.

Get in touch