Cybersecurity and Responsible Disclosure Policy
Effective Date: August 9, 2026 Last Updated: August 9, 2026
This page has two parts. Part A describes our general approach to protecting information. Part B tells security researchers how to report a vulnerability in our website and what we ask of them in return.
Part A: Cybersecurity Commitment
Our Approach
DERECHO maintains or develops safeguards appropriate to its operations and the nature of the information involved. We describe our approach at a general level. We do not publish the details of our security implementation, and the absence of a specific control from this page should not be read either as confirmation or denial that we use it.
This Website Holds No Controlled or Sensitive Data
This website is a public marketing property presenting representations of research and development. It does not host, store, process, or provide access to classified information, Controlled Unclassified Information, export-controlled technical data, customer data, or operational systems. It has no user accounts, no forms, and sets no cookies. Contact with DERECHO is by email, and correspondents are instructed that messages must contain no controlled information.
Risk-Based Protection
We apply protection in proportion to risk. Information that would cause greater harm if disclosed, altered, or lost receives greater protection.
Confidentiality, Integrity, and Availability
We work to keep information from being disclosed to those who should not have it, to keep it accurate and unaltered, and to keep it available to those who need it.
Data Minimization
We seek to collect and retain only what we need. Information not held cannot be lost.
Access Control
Access to systems and information is granted based on business need and is reviewed as roles change.
Vendor Awareness
We consider security when selecting and working with providers, and we recognize that information we entrust to a third party remains our responsibility.
Security Awareness
Personnel receive guidance on protecting information, recognizing common attacks, and reporting suspected incidents.
Incident Handling
We maintain a process for identifying, assessing, containing, and responding to suspected security incidents, including notification where required by law or contract.
Business Resilience
We consider continuity and recovery so that a disruption does not become a permanent loss.
Periodic Review
We review this approach as our operations, obligations, and threat environment change.
Legal and Contractual Obligations
Some of our work may be subject to specific security requirements imposed by law, regulation, or contract. Where such requirements apply, we implement them as required by the applicable instrument. This page describes general practice and is not a representation of compliance with any particular framework, standard, or certification.
Reporting a Security Concern
If you believe you have found a security issue affecting DERECHO, see Part B.
Part B: Responsible Vulnerability Disclosure
1. Purpose
We want to know about security problems in our public website. This section explains what you may test, how to report what you find, and what you can expect from us.
2. Authorized Scope
The following is in scope:
- Publicly accessible web properties at derechodefense.com and its subdomains that are owned and operated by DERECHO
Nothing else is in scope.
3. Out of Scope
The following are out of scope and must not be tested:
- Physical products, hardware, and prototypes
- Aircraft and air systems
- Rocket hardware
- Soldier systems and worn equipment
- Radios, radio frequency systems, and waveforms
- Embedded systems and firmware
- Private source code repositories
- Cloud accounts and administrative consoles
- Third-party systems and services, including those used by DERECHO
- Government systems and networks
- Customer and partner systems
- Facility networks and physical security systems
- Employee, contractor, and personal accounts and devices
- Any person, as a target of social engineering
If you are unsure whether something is in scope, ask before testing. An asset being reachable from the internet does not place it in scope.
4. Good-Faith Research
We consider research conducted in good faith and in compliance with this policy to be authorized. Good faith means you are trying to find and report a problem, not exploit it, and that you stop as soon as you have enough to demonstrate the issue.
5. Testing Limitations
Test only against in-scope assets. Do not degrade service for others. Use your own accounts and test data. Stop immediately if you encounter personal information, credentials, controlled information, or anything that appears sensitive.
6. Minimum Necessary Exploitation
Demonstrate the vulnerability with the least intrusive action that establishes it. Do not pivot, escalate beyond what is needed to show impact, establish persistence, or access data beyond a minimal proof.
7. Data Protection
If you access data that is not yours, stop, do not save or copy it beyond what is needed to report, tell us what you encountered, and delete it when we confirm receipt. Do not disclose it to anyone else.
8. How to Report
Send your report by email to info@derechodefense.com with "Security report" in the subject line.
Do not include exploit code beyond what is necessary to demonstrate the issue, and do not include classified information, Controlled Unclassified Information, export-controlled technical data, or third-party proprietary information in your report.
9. What to Include
- The affected URL, endpoint, or component
- The vulnerability type
- Steps to reproduce, in enough detail that we can follow them
- What an attacker could accomplish
- Any prerequisites such as a particular browser or account state
- Supporting evidence such as a request or response capture, redacted of any sensitive data
- How you would like to be credited, if at all
Reports in English are preferred.
10. Acknowledgement
We intend to acknowledge reports promptly. We do not commit to a specific acknowledgement time.
11. Coordination
We ask that you work with us while we investigate and remediate, and that you give us a reasonable opportunity to address the issue before disclosing it. We will tell you what we find and when we have addressed it.
12. Public Disclosure
Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to remediate and have coordinated timing with you. We will not ask you to stay silent indefinitely.
13. No Bounty
DERECHO does not operate a paid bug bounty program and does not offer monetary rewards. If you are looking for compensation, this is not that program.
14. No Guaranteed Response or Remediation Time
We do not commit to a response time, a remediation time, or an outcome. We will act on reports based on severity and available resources.
15. Third-Party Services
Some functionality on our website may be provided by third parties. Vulnerabilities in a third party's own infrastructure should be reported to that third party under its policy. Do not test a vendor's systems under this policy. If you believe a third-party issue affects us, tell us and we will follow up with the vendor.
16. Prohibited Activity
The following are prohibited under this policy:
- Denial-of-service or resource-exhaustion testing
- Physical attacks against facilities, personnel, or equipment
- Social engineering of any kind, including phishing, pretexting, and vishing
- Credential stuffing or use of credentials you did not create
- Extortion, threats, or any demand for payment in exchange for withholding a report
- Establishing persistence on any system
- Deploying malware, backdoors, or unauthorized tooling
- Destructive testing, including deletion or modification of data
- Accessing, collecting, or exfiltrating personal information beyond a minimal proof
- Accessing government, customer, partner, or other third-party systems
- Testing a vendor's infrastructure without that vendor's permission
- Public disclosure before reasonable coordination
- Any activity that violates applicable law
Conduct outside this policy is not authorized.
17. Safe Harbor
If you conduct security research in good faith and in compliance with this policy, DERECHO will not pursue civil action against you or refer the matter to law enforcement for that research. We will make this position known if a third party initiates action against you for research conducted in compliance with this policy.
This does not waive the rights of any third party, and it does not authorize activity against systems DERECHO does not own or control. If legal action is initiated by a third party against you, this policy does not protect you from it.
18. Contact
Email info@derechodefense.com with "Security report" in the subject line.
