SECURITY
BY DEFAULT.
Software engineering without uncompromising security is technical debt. We welcome ethical security researchers and maintain rigorous hardening standards across all client systems.
Our Security Philosophy
At EthosCore, security is not treated as a perimeter checklist or a last-minute audit. We build with a “Secure by Default” architecture:
Continuous dependency vulnerability scanning (Dependabot / Snyk) and automated SAST analysis integrated into CI/CD deployment pipelines.
Zero shared developer master keys. Granular IAM role segregation with hardware-backed WebAuthn/TOTP 2FA required across all internal tooling.
Codebase & Infrastructure Isolation
We build mission-critical enterprise systems (such as offline-first POS systems, ERPs, and fintech-adjacent software). To protect client assets:
- Air-Gapped Repositories: Client codebases exist in completely segregated repositories. No shared databases, test fixtures, or shared API keys exist across client accounts.
- Sanitized Staging Data: Production client customer data is never cloned directly into development environments without algorithmic pseudonymization and PII masking.
- Secret Management: Environment variables and encryption keys are injected via encrypted vaults (Doppler / Infisical / AWS Secrets Manager) and never committed to source control.
Responsible Disclosure & Safe Harbor
We actively encourage security practitioners and independent researchers to test our public systems within the bounds of this policy.
If you conduct vulnerability research in good faith and adhere strictly to the guidelines outlined in this disclosure policy, EthosCore will not pursue legal action, will not initiate law enforcement inquiries against you, and will cooperate transparently to understand and remediate the issue.
How to Report a Vulnerability
Please send all vulnerability discoveries directly to security@ethoscore.com.
To help us triage and resolve the issue quickly, please include:
Response Timeline & Triage SLA
We hold ourselves to disciplined response windows for all credible vulnerability reports:
| Stage | Target Timeframe | Action Item |
|---|---|---|
| Initial Acknowledgment | ≤ 24 Hours | Human confirmation of report receipt by engineering leadership. |
| Technical Triage | ≤ 72 Hours | Reproduction of vulnerability and assignment of CVSS severity score. |
| Remediation Cadence | Every 48 Hours | Regular status updates sent to reporter until patch deployment. |
| Public Disclosure | Coordinated | Mutual release only after full production deployment of fix. |
Prohibited Activities
The following activities void safe harbor protection and are strictly prohibited:
- Volumetric Denial of Service (DoS / DDoS) testing or automated high-rate fuzzing that degrades service for others.
- Phishing, social engineering, pretexting, or physical intrusions against EthosCore engineers or offices.
- Extracting, modifying, deleting, or retaining any customer or live production database records.
- Publicly disclosing details before an agreed-upon coordinated disclosure timeline.
Encrypted Communication & PGP
For critical or zero-day findings, you may encrypt your communication using our public security channel: