Vulnerability Disclosure Policy
At dkent.net, we maintain the security of our systems and the protection of our users’ data as a top priority. We appreciate the work of security researchers who help us keep our platform safe. This policy outlines the steps for reporting vulnerabilities and the guidelines for doing so responsibly.
1. Responsible Disclosure Guidelines
To encourage responsible reporting, we ask that you:
- Give us a reasonable amount of time to investigate and remediate the issue before making any information public.
- Avoid privacy violations, destruction of data, and interruption or degradation of our service.
- Only interact with accounts you own or with the explicit permission of the account holder.
- Do not use automated scanners that may cause Denial of Service (DoS) or performance issues.
2. Out of Scope
The following activities are strictly prohibited:
- Denial of Service (DoS/DDoS) attacks.
- Social engineering or phishing of our staff or users.
- Physical attacks against our infrastructure.
- Spamming.
3. How to Report a Vulnerability
If you believe you have found a security vulnerability, please send a detailed report to:
support@dkent.net
Please include the following in your report:
- A description of the vulnerability and its potential impact.
- Step-by-step instructions to reproduce the issue (proof-of-concept).
- Your name (or alias) and any links you would like us to include in our Acknowledgements page if the report is valid.
We recommend encrypting your report using our PGP Key.
4. Our Commitment
If you follow these guidelines, we commit to:
- Acknowledging receipt of your report within 3–5 business days.
- Providing an estimated timeframe for a fix.
- Notifying you when the vulnerability has been resolved.
- Adding your name to our Acknowledgements page to recognize your contribution.