Security
Last updated: May 23, 2026
Devancore builds enterprise software for regulated operating environments. Security is part of the product design, customer onboarding, vendor review, and support process.
Security Contact
For vulnerability reports, security questions, or vendor security questionnaire requests, contact security@devancore.com. For general business inquiries, use access@devancore.com.
Security Practices
Our security program is designed around practical controls, including:
- Role-scoped access control and least-privilege permissions
- Tenant-aware application context for customer-scoped workflows
- OTP-based multi-factor authentication support for authenticated users
- TLS for data in transit and encryption at rest where supported by the relevant cloud service or storage layer
- AWS KMS for selected application-level encryption, including sensitive authentication and wallet-related material where implemented
- AWS Secrets Manager for environment secrets and operational credentials
- AWS-based operating environment, including managed compute, database, storage, secrets management, logging, and network controls
- Audit activity and lifecycle event logging for security-relevant and operational activity
- Environment separation for production and non-production systems as environments are introduced
- Vendor review for material service providers
- Secure development practices, code review, and incident triage procedures
Customer Environments
Security controls for a customer deployment may depend on the customer agreement, configuration, integrations, hosting model, permissions, data flows, and operational responsibilities. Devancore can support customer security review and vendor diligence under appropriate confidentiality terms.
Responsible Disclosure
We ask security researchers to report vulnerabilities privately so we can review and address them before public disclosure. We will acknowledge credible reports within two business days. We will not pursue legal action against researchers who act in good faith, avoid privacy violations, do not disrupt service, do not access or exfiltrate data beyond what is necessary to prove the issue, do not use extortion or public pressure tactics, and follow this policy.
Devancore does not offer a public bug bounty unless a separate written agreement says so. Submission of a report does not create a right to compensation.
In Scope
The following systems are in scope for vulnerability reports:
- devancore.com
- Public Devancore web applications or APIs expressly identified by Devancore as in scope
Out of Scope
The following are out of scope:
- Social engineering, phishing, or pretexting
- Physical attacks against facilities, employees, vendors, or customers
- Denial-of-service or resource-exhaustion testing
- Spam, brute force, credential stuffing, or automated high-volume testing
- Accessing, modifying, deleting, or exfiltrating data that is not necessary to prove the issue
- Persistence, lateral movement, privilege escalation beyond what is necessary to demonstrate impact, or post-exploitation activity
- Public disclosure before Devancore has had a reasonable opportunity to investigate and remediate
- Issues affecting third-party services outside Devancore control
What to Include
A useful report includes:
- A clear description of the issue
- Steps to reproduce
- Potential impact
- Relevant URLs, screenshots, logs, or proof-of-concept details
- Your preferred contact information
No Guarantee
No system is perfectly secure. This page describes our security contact and general practices. It does not create a warranty, certification, audit opinion, regulatory approval, service-level commitment, or guarantee that any system is free from risk. Customer-specific commitments, if any, are governed only by the applicable signed agreement.