GOVERNANCE // 03 SECURITY DISCLOSURES
REVISED: OCTOBER 2026 · STANDARDS COMPLIANT

SECURITY
BY DEFAULT.

Software engineering without uncompromising security is technical debt. We welcome ethical security researchers and maintain rigorous hardening standards across all client systems.

SECTION 01

Our Security Philosophy

At EthosCore, security is not treated as a perimeter checklist or a last-minute audit. We build with a “Secure by Default” architecture:

Static & Dependency Auditing

Continuous dependency vulnerability scanning (Dependabot / Snyk) and automated SAST analysis integrated into CI/CD deployment pipelines.

Principle of Least Privilege

Zero shared developer master keys. Granular IAM role segregation with hardware-backed WebAuthn/TOTP 2FA required across all internal tooling.

SECTION 02

Codebase & Infrastructure Isolation

We build mission-critical enterprise systems (such as offline-first POS systems, ERPs, and fintech-adjacent software). To protect client assets:

  • Air-Gapped Repositories: Client codebases exist in completely segregated repositories. No shared databases, test fixtures, or shared API keys exist across client accounts.
  • Sanitized Staging Data: Production client customer data is never cloned directly into development environments without algorithmic pseudonymization and PII masking.
  • Secret Management: Environment variables and encryption keys are injected via encrypted vaults (Doppler / Infisical / AWS Secrets Manager) and never committed to source control.
SECTION 03

Responsible Disclosure & Safe Harbor

We actively encourage security practitioners and independent researchers to test our public systems within the bounds of this policy.

Our Safe Harbor Pledge

If you conduct vulnerability research in good faith and adhere strictly to the guidelines outlined in this disclosure policy, EthosCore will not pursue legal action, will not initiate law enforcement inquiries against you, and will cooperate transparently to understand and remediate the issue.

SECTION 04

How to Report a Vulnerability

Please send all vulnerability discoveries directly to security@ethoscore.com.

To help us triage and resolve the issue quickly, please include:

1. Description and potential impact of the issue.
2. Exact endpoint, URL, or service component affected.
3. Clear, reproducible step-by-step instructions or minimal Proof of Concept (PoC).
4. Your preferred name/handle if you wish to be credited in our advisory acknowledgments.
SECTION 05

Response Timeline & Triage SLA

We hold ourselves to disciplined response windows for all credible vulnerability reports:

StageTarget TimeframeAction Item
Initial Acknowledgment≤ 24 HoursHuman confirmation of report receipt by engineering leadership.
Technical Triage≤ 72 HoursReproduction of vulnerability and assignment of CVSS severity score.
Remediation CadenceEvery 48 HoursRegular status updates sent to reporter until patch deployment.
Public DisclosureCoordinatedMutual release only after full production deployment of fix.
SECTION 06

Prohibited Activities

The following activities void safe harbor protection and are strictly prohibited:

Out-of-Scope Research Actions:
  • Volumetric Denial of Service (DoS / DDoS) testing or automated high-rate fuzzing that degrades service for others.
  • Phishing, social engineering, pretexting, or physical intrusions against EthosCore engineers or offices.
  • Extracting, modifying, deleting, or retaining any customer or live production database records.
  • Publicly disclosing details before an agreed-upon coordinated disclosure timeline.
SECTION 07

Encrypted Communication & PGP

For critical or zero-day findings, you may encrypt your communication using our public security channel:

// ETHOSCORE SECURITY ENCRYPTION CHANNEL
Fingerprint: 4E9A 782B C3F1 8092 11E5 F6D4 38A0 9B7E 22A1 6F09
Recipient: security@ethoscore.com
Supported algorithms: RSA 4096 / Ed25519 · TLS 1.3 Strict In Transit