Responsible Disclosure
We welcome responsible security research into our systems. This policy explains how to report vulnerabilities, what to expect from us, and the protections we extend to researchers who act in good faith.
1. Our commitment
Deep Guard takes the security of its own infrastructure, website, and client-facing systems seriously. We welcome reports from security researchers who identify vulnerabilities affecting our systems and we are committed to working with the security community in good faith.
We will acknowledge receipt of every report, investigate promptly, and where a valid vulnerability is confirmed, we will work to remediate it in a reasonable timeframe and keep you informed of our progress. We will not pursue legal action against researchers who act in accordance with this policy.
2. Scope
This policy covers vulnerabilities affecting systems owned and operated by Deep Guard, including our public website (deepguard.io and any subdomains), our client portal and authentication systems, our email infrastructure, and any APIs we operate.
This policy does not cover vulnerabilities in third-party software, libraries, or services that we use but do not control. It also does not cover vulnerabilities in client protocols or smart contracts — those should be reported directly to the relevant project team. If you are unsure whether a system falls within scope, please reach out before proceeding and we will clarify.
3. What to report
We are interested in reports of the following classes of vulnerability affecting in-scope systems: authentication bypass or broken access control, injection vulnerabilities (SQL, command, template, or similar), cross-site scripting (XSS) or cross-site request forgery (CSRF), sensitive data exposure or insecure direct object references, server-side request forgery (SSRF), subdomain takeover, and significant security misconfigurations.
We are not interested in reports of the following: missing security headers that do not represent a practical exploitable risk, clickjacking on pages that do not perform sensitive actions, SPF or DMARC configurations that do not result in a demonstrable vulnerability, rate limiting on non-sensitive endpoints, or results from automated scanners without evidence of an actual vulnerability.
4. How to report
Please send vulnerability reports to security@deepguard.io. Include a clear description of the vulnerability, the affected system or URL, the steps required to reproduce the issue, and the potential impact if the vulnerability were exploited.
Where possible, include supporting evidence such as screenshots, proof-of-concept code, or HTTP request/response captures. Do not exfiltrate, alter, or destroy data in the course of your testing. If you have accessed data belonging to other users or to Deep Guard, please disclose this in your report and delete any copies you hold.
5. Encryption
If your report contains sensitive details — such as proof-of-concept code, credentials, or information that could cause harm if intercepted — we encourage you to encrypt your message using PGP. Our public key is available on request by emailing security@deepguard.io. You may also use Signal for initial contact; please request our handle in the same email.
6. Our process
When we receive a report we will acknowledge it within two business days. We will investigate and confirm whether the reported issue is a valid vulnerability affecting in-scope systems, typically within five business days of acknowledgement for straightforward reports.
If the report is valid, we will work to develop and deploy a fix. We will keep you informed at each stage — confirmation, remediation, and deployment — and we will not ask you to keep the issue secret indefinitely. We will agree a disclosure timeline with you, typically 90 days from the date we confirm the vulnerability, in line with industry-standard coordinated disclosure practice.
7. Safe harbour
Deep Guard will not initiate legal action against researchers who: report a vulnerability in accordance with this policy before disclosing it publicly, make a good-faith effort to avoid privacy violations, disruption of services, and data destruction during their research, do not access or modify data belonging to other parties beyond what is necessary to demonstrate the vulnerability, and do not demand payment in exchange for withholding the report or the details of the vulnerability.
We ask that you give us a reasonable opportunity to remediate before public disclosure. If you believe we have failed to respond or remediate in a reasonable time, you may proceed with disclosure after giving us at least 90 days from the date of your initial report.
8. Exclusions
The following activities are explicitly not authorised under this policy: denial-of-service attacks or any testing that generates excessive load on our systems, social engineering or phishing of Deep Guard staff or clients, physical security testing, accessing accounts that do not belong to you without the account holder's explicit prior consent, and testing against systems not listed in scope.
Researchers who engage in excluded activities may not benefit from the safe harbour provisions of this policy.
9. Recognition
We do not currently operate a paid bug bounty programme. We will, however, recognise legitimate reporters with public credit in a hall of fame on this website (with your permission) and a written acknowledgement. We may offer discretionary rewards for high-severity findings at our sole discretion.
10. Changes to this policy
We may update this Responsible Disclosure Policy from time to time. The most current version will always be available at deepguard.io/responsible-disclosure. Material changes will be noted with a revised effective date.
11. Contact
For vulnerability reports: security@deepguard.io For policy questions: legal@deepguard.io