Report a vulnerability
Send reports to security@seifertdynamics.com with reproduction steps and impact. We acknowledge good-faith reports and coordinate remediation.
Security at Seifert Dynamics is addressed through architecture, process, access control, review, and disciplined communication — on this website, in our delivery pipeline, and inside customer deployments.
01 / Security
Send reports to security@seifertdynamics.com with reproduction steps and impact. We acknowledge good-faith reports and coordinate remediation.
Scoped access, mandatory change review, dependency awareness, secrets hygiene, and implementation-specific controls across the codebase and delivery pipeline.
Deployment controls are tailored to each customer’s environment, data sensitivity, and operational risk — and documented so they can be audited, not just asserted.
This policy covers seifertdynamics.com and internet-facing services operated directly by Seifert Dynamics. Customer-deployed environments are governed by each customer’s own agreements and rules of engagement — do not test them without explicit written authorization from that customer.
Email security@seifertdynamics.com with a clear description of the issue, steps to reproduce, and your assessment of impact. Please do not include live exploit payloads or third-party personal data in the initial message; if the finding is sensitive, say so and we will establish a secure channel.
We aim to acknowledge reports within five business days, keep the reporter informed of remediation progress, and — where the reporter wishes — credit good-faith research once the issue is resolved. We do not currently operate a paid bounty program.
We will not pursue or support legal action against good-faith, non-destructive security research conducted under this policy: no data exfiltration beyond minimal proof of concept, no service disruption, no social engineering of personnel, and no access to data belonging to others.
Denial-of-service testing, spam, physical intrusion, social engineering, and findings on third-party services we do not operate are out of scope. Automated scanning at volumes that degrade service is not authorized.
03 / Process
Collect and process only what is needed for the task. The cheapest data to protect is the data never collected.
Access controls, strong authentication, logging, and separation appropriate to the environment and threat model.
Preserve evidence for troubleshooting, governance, and incident response — and review it on a schedule, not just after something breaks.
Engagement