DV//AI
EDITION 2026.33SINGAPORE
CONTROL NOTE / 02COORDINATED DISCLOSURE

SECURITY / REPORTING PROTOCOL

Preserve evidence.
Minimise harm.

If a boundary fails, report the smallest reproducible proof through the protected channel. Do not turn a finding into a second incident.

01

Make the report actionable

Identify the affected URL or component, prerequisites, minimal reproduction steps, observed impact and a safe suggestion for verification. Remove secrets, personal information and unrelated data from screenshots or proof.

OPEN SECURITY INTAKE
02

Do not create consequence

Do not access, alter, retain or publish other people’s data; degrade service; use social engineering or phishing; test third-party systems; establish persistence; or demand payment. Stop when a finding is established and report it.

This policy is not blanket authorisation, a bug-bounty promise or permission to breach law or third-party terms. Good-faith, proportionate research that follows these boundaries will be handled as a coordinated security report.

03

What to expect

The target is to acknowledge a credible report within three business days, establish a private coordination path and provide a status update within ten business days. Remediation timing depends on severity and system ownership.

Public disclosure should be coordinated after a fix or agreed mitigation is available. There is currently no standing reward programme.

04

One canonical route

Automated security tooling can discover this policy through the RFC 9116 resource. It points to this HTTPS route rather than exposing a mailbox.

VIEW SECURITY.TXT