1. Security commitment
DecisionLayer Systems LLC treats security, privacy, auditability, and controlled change as operating requirements. The corporate website uses HTTPS, restrictive security headers, server-side validation, protected configuration, authenticated email delivery, abuse controls, backups, rollback procedures, and deployment evidence.
2. Report a security concern
Use the protected contact form, select “General,” and begin the subject of your message with Security report. Include the affected URL, a clear description, reproducible steps, impact, and supporting evidence that does not expose unnecessary personal data.
Do not include passwords, private keys, access tokens, or personal information belonging to other people. Our machine-readable disclosure contact is published at /.well-known/security.txt.
3. Scope
This policy covers decisionlayersystems.com and its public corporate-site contact workflow. ShelfCoach, JobReload, and other product environments may publish separate security policies. Obtain written authorization before testing any system not expressly listed as in scope.
4. Good-faith research
Good-faith research should avoid privacy violations, data destruction, service disruption, social engineering, physical intrusion, persistence, and access beyond what is necessary to demonstrate a finding. Stop testing and report promptly if you encounter nonpublic data.
DecisionLayer Systems intends to treat research conducted carefully, lawfully, and consistently with this policy as authorized for the limited purpose of reporting the issue. This policy does not authorize conduct prohibited by law or by third-party terms.
5. Prohibited testing
- Denial-of-service, load testing, or automated traffic that degrades availability.
- Phishing, pretexting, social engineering, or targeting employees, vendors, or users.
- Physical security testing or attempts to access offices, devices, or infrastructure providers.
- Destructive actions, data alteration, malware, persistence, or exfiltration.
- Publishing a vulnerability before a reasonable remediation and disclosure process.
- Testing third-party services without permission from their owner.
6. What to expect
We aim to acknowledge a complete report within five business days, evaluate severity and reproducibility, and communicate material status changes when practical. Resolution time depends on complexity, impact, dependencies, and the safety of deploying a fix. This is not a paid bug-bounty program, and no reward is promised.
7. Coordinated disclosure
Please allow reasonable time to investigate and remediate before public disclosure. We may ask you to delay publication when immediate disclosure would materially increase risk. Credit may be offered when appropriate and requested, but we will not identify a reporter publicly without permission.
8. Policy updates
We may revise this policy as the company, website, or product portfolio changes. The effective date above identifies the current version.
