Skip to main content
DEFENZ

Responsible disclosure

Security

Testing and disclosure rules — read before any submission.

Disclosure
  1. Test scope only

    Our virtual staging environments are for testing only. Production infrastructure is never a target.

  2. 90-day coordinated disclosure

    No exploit publication before fix + written consent. Duplicates are grouped, not penalized.

  3. Privacy

    Do not exfiltrate personal data beyond minimal proof. Report and delete.

  4. Critical infrastructure

    Security reports are handled by our triage team within 48 h. We neither request nor accept destructive testing.