Security is treated as an operational requirement. This page describes the public website security channel and disclosure expectations.
Reporting a security issue
Do not publicly disclose a suspected vulnerability before it can be reviewed. Send good-faith security reports privately to security@sdiptechnologies.com. Include enough detail for the issue to be reproduced without accessing data that does not belong to you.
In scope
Good-faith reports concerning publicly accessible SDIP Technologies web properties may be reviewed. Do not perform denial-of-service testing, destructive testing, social engineering or access data that does not belong to you.
What to include
- Affected URL and feature
- Clear reproduction steps
- Expected and observed behavior
- Potential impact
- Any non-destructive evidence
Our approach
We use restricted services, HTTPS, security headers, backups, health checks and rollback procedures as part of the operating baseline. No system can be guaranteed completely secure.
