Vulnerability Reporting Channel
If you believe you have discovered a security or privacy vulnerability in a DexForce product, you may fill out the template and send the security issue directly to security@dexforce.top. You will receive a confirmation email from DexForce PSIRT within 2 work days, and we will inform you of the progress of issue handling based on the specific situation.
For valid vulnerability reports, we will express our gratitude to the reporter in our official security advisory with their consent.
Confidentiality Mechanism
Given the sensitivity of vulnerability information, to ensure confidentiality, we recommend that you use PGP (Pretty Good Privacy) to encrypt information sent to security@dexforce.top. Our PGP public key (Key ID: E427B07871FBD945; PGP fingerprint: D190 DCD2 949D F6B6 5702 9B7B E427 B078 71FB D945) can be obtained by clicking here.
Throughout the entire vulnerability handling process, DexForce strictly controls the dissemination of vulnerability information and only shares it with relevant personnel. Meanwhile, we also require vulnerability reporters to keep vulnerability information confidential until our customers have access to a complete solution.
Response Range
This vulnerability handling process applies to all hardware, software products or services provided by DexForce.

