DC Associates Group logoDC Associates Group

Home / Security / Vulnerability disclosure

Vulnerability disclosure policy

We welcome good-faith security research into our images, charts, and this website.

Reporting

Email agent@dcassociatesgroup.com with subject "VULN:" (machine-readable contact in /.well-known/security.txt). Include the product and version (or image/AMI id), reproduction steps, and impact. Please don't file security issues on public trackers.

What to expect

  1. Acknowledgment within 2 business days.
  2. Triage verdict within 5 business days.
  3. Fixes ship through our rebuild pipeline — critical issues trigger an event-driven rebuild rather than waiting for the monthly cycle, and appear in the release notes labeled Critical.

Scope & good faith

In scope: our published images and charts, and this website. Out of scope: the cloud marketplaces' own platforms (their policies govern their infrastructure), denial of service, social engineering, and physical attacks. We will not pursue action for good-faith, non-destructive research that respects customer data and applicable law — do not access data that isn't yours or degrade service for others.

We do not currently operate a paid bounty program. This policy is reviewed annually alongside security.txt.