Vulnerability Disclosure Policy

Introduction 

Daitasoft LLC has established a process to receive feedback from security researchers and the public to help improve our security. If you believe you have discovered a cybersecurity vulnerability, privacy issue, exposed data, or any other significant issues (collectively “vulnerabilities” hereafter) in any of our assets, we want to hear from you. This policy outlines steps for reporting vulnerabilities to us, what we expect, and what you can expect from us. 

Assets in Scope 

This policy applies to any digital assets (e.g., information systems and data) owned, operated, or maintained by Daitasoft. 

Assets Out of Scope 

Digital assets not owned by or in the custody of Daitasoft are considered out of scope of this policy. Vulnerabilities discovered or suspected in out-of-scope systems should be reported to the appropriate vendor or applicable authority. 

Personnel (e.g., social engineering, phishing, smishing, vishing) and physical security research may not be conducted.  

Remuneration 

Daitasoft does not offer any financial compensation for submitted vulnerability reports (i.e., a bug bounty is not provided).  

Our Commitments 

When working with us, according to this policy, you can expect us to 

Our Expectations 

In participating in our vulnerability disclosure program in good faith, we ask that you: 

Official Channel

Current Daitasoft customers are encouraged to contact us through existing customer support channels.  

For non-customers, if you need to contact Daitasoft about a potential security issue with one of our products or services, please use the email address vdp@daitasoft.com. The more details you provide, the easier it will be for us to triage and fix the issue. Accordingly, your submission should include the following details: 

If any of the disclosure content submitted to us has sensitive information that requires additional protection, please contact us via the Official Channel, and we will provide a URL for the secure upload of supporting documentation. 

Limitation of Liability 

Security research is performed at your own risk. In no event shall Daitasoft, its affiliates or their employees, contractors, agents, officers, or directors be liable to you, related to your participation in this program, for any damages or losses.  

Safe Harbor Statement 

When conducting vulnerability research according to this policy, we will not pursue or support legal action related to your good-faith security observations or research. 

You are expected, as always, to comply with all applicable laws. If legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. 

If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through our Official Channel before proceeding. 

Note that the Safe Harbor applies only to legal claims under the control of Daitasoft, and the policy does not bind third parties.