Security and Vulnerability Disclosure
Effective and last reviewed: August 14, 2026
Duskbridge wants to hear about security problems in its public web presence before anyone else does. If you believe you have found a vulnerability affecting this website, report it privately through the channels below and Duskbridge will work with you to understand and address it.
Scope
This policy covers the public Duskbridge corporate website at duskbridge.com, duskbridge.ai, duskbridge.net, their www hostnames, and the associated Render hostname. Products and services operated by Duskbridge operating companies have their own disclosure routes; a report about one of them sent here will be forwarded to the right team.
Incident response
Duskbridge maintains a documented incident-response process for this public website. The Chief Technology Officer is the accountable owner; suspected incidents are triaged, contained, investigated, documented, and escalated to the affected operating company, legal review, and customer-notification process as applicable. The contact route below is monitored as the public entry point. The detailed response plan and jurisdictional notice matrix remain internal.
How to report
Email contact@duskbridge.com with “Security report” in the subject line, or use the contact formand select “Security or vulnerability report.” Include the affected URL or endpoint, the steps to reproduce what you observed, and the impact you believe it has. Do not include personal information beyond what the report needs, and do not send passwords, payment information, health data, government identifiers, FCI, CUI, or classified information.
A machine-readable version of this policy is published at /.well-known/security.txt per RFC 9116.
What to expect
Duskbridge acknowledges security reports within 3 business days, keeps the reporter informed while the report is assessed and addressed, and credits reporters who ask for it once a fix ships. Duskbridge does not operate a paid bounty program at this time.
Good-faith research
Duskbridge supports good-faith security research: testing that avoids privacy violations, data destruction, and service degradation, that stops at the minimum access needed to demonstrate the finding, and that gives Duskbridge a reasonable period to remediate before any public disclosure. Do not access, exfiltrate, or retain data that is not yours, do not run denial-of-service or social-engineering attacks, and do not test third-party services in the request path except through their own disclosure programs.
