Coordinated Vulnerability Disclosure Policy
Data Trust Associates (“DTA,” “we,” “our,” or “us”) is committed to protecting the confidentiality, integrity, and availability of the systems, applications, and data we manage. We recognize that independent vulnerability testers play a valuable role in helping identify vulnerabilities that might otherwise go unnoticed.
In this policy, a “vulnerability tester” means any natural or legal person outside DTA who, as permitted under applicable legislation and acting without fraudulent intent or intent to harm, identifies a potential security vulnerability in a DTA system on their own initiative and reports it to us. Vulnerability testers are not engaged, instructed, or paid by DTA, and their testing must stay within the scope set out in Section 2 and comply with the conditions applicable legislation imposes on such testing.
This Coordinated Vulnerability Disclosure (CVD) Policy establishes a clear process for reporting suspected security vulnerabilities discovered in DTA systems, and describes how we work with vulnerability testers to investigate, validate, and remediate reported issues in a responsible and coordinated manner.
This policy is informed by internationally recognized standards for vulnerability disclosure and handling, including ISO/IEC 29147 (Vulnerability Disclosure) and ISO/IEC 30111 (Vulnerability Handling Processes).
1. Scope
1.1 In Scope
This policy applies to vulnerabilities discovered in:
• All externally facing websites, web applications, and APIs owned and operated by Data Trust Associates
• Network infrastructure, servers, and cloud environments owned and managed by DTA
1.2 Out of Scope
The following are not covered by this policy and must not be tested without separate written authorization from DTA:
• Third-party services, products, plugins, or infrastructure not owned or controlled by DTA, even where integrated with DTA systems
• Physical security testing of DTA offices or facilities
• Social engineering attacks against DTA employees, contractors, or clients (e.g. phishing, vishing, pretexting)
• Denial-of-service (DoS/DDoS) testing
• Automated vulnerability scanning that generates high volumes of traffic without prior coordination
• Accessing, modifying, or exfiltrating data belonging to other users or clients without their explicit consent
• Any activity that would violate applicable local, national, or international law
2. Our Commitment
When a vulnerability is reported in accordance with this policy, Data Trust Associates commits to:
• Acknowledge receipt of the report within the timeframes set out in Section 7
• Provide an initial assessment of the report's validity and severity
• Keep the reporter reasonably informed of progress toward resolution
• Treat the report and the reporter's identity as confidential, and not share this information with third parties without consent, except as required by law
• Work collaboratively with the reporter to understand, reproduce, and validate the issue where reasonably possible
• Notify the reporter once the vulnerability has been remediated
3. Obligations for Vulnerability Testers
To help us respond quickly and to keep this process safe for everyone involved, vulnerability testers are asked to:
• Only interact with test accounts you own or for which you have explicit permission to test
• Avoid actions that could result in privacy violations, data destruction, or service interruption
• Refrain from accessing, modifying, downloading, or deleting data that does not belong to you; stop testing and report immediately if you inadvertently access sensitive or personal data
• Avoid exploiting a vulnerability beyond what is strictly necessary to confirm its existence
• Give DTA a reasonable amount of time to investigate and remediate an issue before disclosing it publicly (see Section 8)
• Comply with all applicable laws in the course of your testing
• Communicate in good faith, and refrain from threats, extortion attempts, or demands for compensation in exchange for disclosure or non-disclosure
4. How to Report a Vulnerability
If you believe you have discovered a security vulnerability affecting a DTA system within scope, please report it to:
Email: dp_alert@datatrustassociates.com
This mailbox is monitored by DTA's Information Security / IT function. We recommend publishing a corresponding /.well-known/security.txt file referencing this address, and encourage reporters to encrypt sensitive report details (a PGP key can be added here once available).
5. What to Include in Your Report
To help us triage and validate your report efficiently, please include as much of the following as possible:
• A clear description of the vulnerability and its potential impact
• The system, URL, IP address, or application where the vulnerability was found
• Step-by-step instructions to reproduce the issue
• Proof-of-concept code, screenshots, or video, where applicable
• Any relevant logs or request/response data, with sensitive information redacted
• Your name or handle and preferred contact information, if you would like to be credited or contacted for follow-up
6. Our Response Process & Timelines
Once a report is received, DTA aims to follow the timeframes below. These are targets rather than guarantees; actual timing may vary depending on complexity, severity, and coordination required with third parties.
Stage Target Timeframe
Acknowledgment of report Within 5 business days
Initial triage & severity assessment Within 15 business days
Status updates to the reporter At least every 20 business days until resolved
Remediation – Critical / High severity Within 30–60 days, depending on complexity
Remediation – Medium / Low severity Within 90 days, depending on complexity
7. Coordinated Disclosure
DTA follows the principle of coordinated disclosure: details of a reported vulnerability should not be publicly disclosed until DTA has had a reasonable opportunity to investigate, remediate, and notify affected parties.
• Standard disclosure window: 90 days from acknowledgment of the report, or upon remediation, whichever occurs first, unless otherwise agreed in writing
• Where remediation requires additional time, DTA will communicate proactively with the reporter and seek to agree on a mutually acceptable timeline
• With the reporter's consent, DTA may publicly credit the vulnerability tester for their contribution once the issue is resolved
8. No Compensation
Data Trust Associates does not run a bug bounty programme. We do not pay for vulnerability reports, and no reward of any kind is offered under this policy.
9. Legal Notice
This policy describes how Datatrust Associates prefers vulnerabilities to be reported and how we intend to respond. It does not create a contractual relationship or grant any rights to reporters, and it is not a substitute for legal advice.
Individuals conducting security testing remain solely responsible for ensuring their activities comply with all applicable laws. DTA reserves the right to determine, at its sole discretion, whether reported activity was conducted in accordance with this policy and its stated scope, and reserves all other rights with respect to activity that falls outside this policy, including unauthorized access to systems or data.
10. Policy Review and Updates
This policy will be reviewed periodically and updated as needed to reflect changes in DTA's systems, legal requirements, or industry best practice. The current version number and effective date appear on the title page of this document.
Version 1.0
Date 1st September 2026
Description Initial policy published
11. Contact
For questions about this policy, or to submit a vulnerability report, please contact:
Datatrust Associates
Information Security / IT
Email: dp_alert@datatrustassociates.com