Responsible disclosure
Security reports are read first.
If you believe you have found a vulnerability in a DSI product or in this website, we want to hear about it, and we will work with you to understand and remediate it.
How to report
Use the contact form with the Security · vulnerability disclosure enquiry type. Reports are routed directly to the engineering team. Please include:
- —The affected product, page, or endpoint
- —Steps to reproduce, or a minimal proof of concept
- —The impact you believe the issue has
- —How we can reach you for follow-up
What to expect
Acknowledgement
We confirm receipt within two working days and keep you informed as we investigate.
Good-faith research
We will not pursue action against research conducted in good faith within the guidelines on this page.
Credit
With your consent, we credit the reporter once a fix has shipped.
Guidelines
- —Do not access, modify, or exfiltrate data that is not yours; use test accounts and minimal proof-of-concept payloads.
- —Do not degrade the service for others: no denial-of-service, spam, or social engineering of DSI staff or customers.
- —Give us reasonable time to remediate before any public disclosure.