Security Architecture & Responsible Disclosure
Last Updated: August 30, 2026 · Security Officer: security@dosvectis.com
1. Security Architecture & Core Posture
DosVectis applies a defense-in-depth, zero-trust security architecture across all client deliveries and internal infrastructure. We enforce security-as-code and automated vulnerability gating at every commit.
- Zero Standing Privileges: JIT administrative access with multi-factor authentication (FIDO2/WebAuthn hardware keys required).
- Encryption Standards: All data at rest is encrypted with AES-256 (KMS envelope encryption). Data in transit requires TLS 1.3 with strict HSTS and PFS cipher suites.
- Continuous Scanning: Automated AST (Static Application Security Testing), container vulnerability scanning (Trivy), and secret leak detection (GitGuardian) enforced in CI/CD lanes.
2. Responsible Vulnerability Disclosure
We welcome reports from security researchers and practitioners. If you believe you have discovered a vulnerability in our public web properties or open repositories, please report it responsibly according to the following principles:
- Give us a reasonable timeframe (minimum 30 days) to mitigate and verify the issue before public disclosure.
- Do not execute denial of service (DoS/DDoS) attacks or automated brute-force scanning that disrupts active services.
- Do not access, modify, or destroy customer or third-party data.
- Encrypt all sensitive finding reports using our public PGP key below.
3. PGP Public Key for Encrypted Submissions
Fingerprint: 4A9F 82B1 0E7C 3D29 55A1 FC09 8812 770E B9A0 C821
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQGNBGizkpABDACyvP3+ZF0gKq7kVtHaNwqYM7eJcjpNrJbR1OPHfXRwK3Gv
9TmWqXFJlD8bE2xUoiAZnRK4sYwTpN6HmLqQeX9vBdY2cOoFI7tVj8JkPzM1
HqDsRnGaWxKm5TFjbEoLpBkXdMvW4h3RzUn7NYqSiCeA2mPdKjFHrtBvYkLp
9xNwMcQoZu8VrTaHbEqJsKfP3dGYn6WRXt5LAvoiUcMkDqBpF7eNsHjKwRTm
4XvGCfYbN2PIoQEqkMaVzSTHuLwDpnKJ9rYWc3BqFtX6OMhIePsZvgCR8TdA
fwLKmNQJ5oXpHiBrTueDcMYk2sNLwRgA7VqP4tOzFjCkXBhsUmWEI6yvJDnl
3pKMcfQwTNbHsGrXkuYoZAqP8eV2mFiCDjLtR5WBnhOxIEaUvK1pYS7gzdMT
fNQwArB4XkjOHe6LmPsGvUcIqTDZ3byR9nhY2WFoC5MtKEsXpJvuB8QdgiAL
NrFkHwYmZcTqO6PAEEEAEbQnRG9zVmVjdGlzIFNlY3VyaXR5IDxzZWN1cml0
eUBkb3N2ZWN0aXMuY29tPokB1AQTAQoAPhYhBEqfgrEO fDTD9lXBCYgSdw65
oMghhAUCaLOSkAIbAwUJA8JnAAULCQgHAgYVCgkICwIEFgIDAQIeAQIXgAAK
CRCIEndwuaDIIYxnC/4i5vKpGsxNt2TqhRmnQaM3u9Fm7iJcB5YeXQAloLTq
VrMjB8Fd7MkEqPpNwjHYz3KfxbQwcLT6FgAVsRnUoW2mZP8R3kDiYeXqCpBr
oWvTl7Nj4aU9GKhDmFYpSzCE3WbXqVkO9mTu1P8dJ7N6hABvFgGqIMzKrE2X
eBnT5oLJqMRwHkfZyUd3PA8nSCmvBXToQiKl4W7pF2DmHsNr9YcE6JuRxbPA
fVG3LMiTwkQpoO1s8CUAV7yB5R3VdKg6pEFNjXWaHYq2TmDcZLsuInO8bPeQ
M4hKvzU1r9A0WjF6GBeYNdskQT7mPXoChkLqIJpBnDRSuyEsH4WqrVcOiOGk
JfT2v6YXAbM5FnrQhzWcE8K3tSbGmP9C7jlVkOupZiDdewNxH2XR0fU4qBcA
E5uoKPLVMaTgSi1h3RQyjZN7pcF0YBwKITqmv4GdOcXnb8JstK6uWHP92Elk
pVDoYwqMzUNTrnG7OA==
=k7Hn
-----END PGP PUBLIC KEY BLOCK-----4. Bug Bounty & Safe Harbor Guidelines
Researchers operating in good faith who comply with our disclosure policy will be granted safe harbor. We will not pursue legal action against security testing performed in accordance with these guidelines.
Security Contact & Incident Desk
Send vulnerability reports, PGP encrypted findings, or compliance verification requests to security@dosvectis.com. SLA response within 12 hours for critical severity reports.