Security
Security Policy
& Disclosure
How to responsibly report security issues to DGRC Consulting — for this website and the systems we build and secure.
Reporting a vulnerability
If you've discovered a security vulnerability on this website or in a system DGRC Consulting manages, please report it responsibly. We take security seriously — it's our business.
Contact: dan@dgrc.consulting
Preferred: Email with as much detail as possible. Include steps to reproduce, the affected system/URL, and the impact you observed.
What we ask
- Give us a reasonable time to respond and fix before disclosing publicly.
- Don't access, modify, or exfiltrate data beyond what's needed to demonstrate the issue.
- Don't perform destructive testing, denial-of-service, or social engineering against this site.
- Don't test systems you don't own or have authorization for.
What we do
- Acknowledge your report promptly.
- Investigate and confirm the issue.
- Remediate the vulnerability.
- Credit you for responsible disclosure (if you'd like).
Out of scope
Third-party services and systems not operated by DGRC Consulting are out of scope for testing through this policy. This site is a static marketing site — it has no user accounts, payment processing, or sensitive data storage.
Have a security question?
Whether it's a report or a question about securing your own business, I'm glad to help.
Get in touch