dgxcode

Contact

Security engagements, vulnerability reports, and disclosure coordination all go to the same inbox.

Channels

Email — engagements & reports security@dgxcode.com Open mail app
Email — general support@dgxcode.com Open mail app
Telegram — direct @dgxcode Open Telegram
Telegram — announcements (one-way) t.me/dgxcodex Open Telegram

Broadcast channel for disclosures and write-up announcements. It is not monitored for reports — use email for anything time-sensitive.

Responsible disclosure policy

If you found a security issue in a Dgxcode property or in something I maintain, thank you — please report it privately. I handle reports under coordinated disclosure and I do not treat good-faith research as an attack.

What to include

  • The affected URL, endpoint, package, or repository and version
  • Step-by-step reproduction, including the request you sent
  • The impact: whose data or which action an attacker reaches
  • Whether the issue is public or already being exploited, as far as you know
  • How you want to be credited, and where to send updates

What I ask you not to do

  • Denial-of-service, stress, or brute-force testing
  • Social engineering of staff, contractors, or support channels
  • Reading, modifying, or deleting data that is not yours — stop at proof of exposure
  • Automated scanning at a volume that degrades service for other users
  • Publishing details before a fix ships or an agreed disclosure date passes

What you get back

  1. Acknowledgement within 3 business days of your report
  2. A triage decision: in scope, out of scope, or duplicate, with reasoning
  3. A fix timeline and an update when the fix ships
  4. Credit in the advisory on request, and no legal action for research that stays inside these terms

Safe harbour

Research that follows this policy, stays inside the affected property, and is reported privately before disclosure is considered authorized and good-faith. I will not pursue legal action for it. If a third party is involved, I will say so early rather than let you guess.

Encrypted mail

No PGP key is published yet. If you need confidentiality in transit, say so in your first message and I will arrange a key or an alternate channel before you send details.

Machine-readable policy

This policy is also published as security.txt at /.well-known/security.txt (RFC 9116).