Security

Last updated: May 23, 2026

Devancore builds enterprise software for regulated operating environments. Security is part of the product design, customer onboarding, vendor review, and support process.

Security Contact

For vulnerability reports, security questions, or vendor security questionnaire requests, contact . For general business inquiries, use .

Security Practices

Our security program is designed around practical controls, including:

  • Role-scoped access control and least-privilege permissions
  • Tenant-aware application context for customer-scoped workflows
  • OTP-based multi-factor authentication support for authenticated users
  • TLS for data in transit and encryption at rest where supported by the relevant cloud service or storage layer
  • AWS KMS for selected application-level encryption, including sensitive authentication and wallet-related material where implemented
  • AWS Secrets Manager for environment secrets and operational credentials
  • AWS-based operating environment, including managed compute, database, storage, secrets management, logging, and network controls
  • Audit activity and lifecycle event logging for security-relevant and operational activity
  • Environment separation for production and non-production systems as environments are introduced
  • Vendor review for material service providers
  • Secure development practices, code review, and incident triage procedures

Customer Environments

Security controls for a customer deployment may depend on the customer agreement, configuration, integrations, hosting model, permissions, data flows, and operational responsibilities. Devancore can support customer security review and vendor diligence under appropriate confidentiality terms.

Responsible Disclosure

We ask security researchers to report vulnerabilities privately so we can review and address them before public disclosure. We will acknowledge credible reports within two business days. We will not pursue legal action against researchers who act in good faith, avoid privacy violations, do not disrupt service, do not access or exfiltrate data beyond what is necessary to prove the issue, do not use extortion or public pressure tactics, and follow this policy.

Devancore does not offer a public bug bounty unless a separate written agreement says so. Submission of a report does not create a right to compensation.

In Scope

The following systems are in scope for vulnerability reports:

  • devancore.com
  • Public Devancore web applications or APIs expressly identified by Devancore as in scope

Out of Scope

The following are out of scope:

  • Social engineering, phishing, or pretexting
  • Physical attacks against facilities, employees, vendors, or customers
  • Denial-of-service or resource-exhaustion testing
  • Spam, brute force, credential stuffing, or automated high-volume testing
  • Accessing, modifying, deleting, or exfiltrating data that is not necessary to prove the issue
  • Persistence, lateral movement, privilege escalation beyond what is necessary to demonstrate impact, or post-exploitation activity
  • Public disclosure before Devancore has had a reasonable opportunity to investigate and remediate
  • Issues affecting third-party services outside Devancore control

What to Include

A useful report includes:

  • A clear description of the issue
  • Steps to reproduce
  • Potential impact
  • Relevant URLs, screenshots, logs, or proof-of-concept details
  • Your preferred contact information

No Guarantee

No system is perfectly secure. This page describes our security contact and general practices. It does not create a warranty, certification, audit opinion, regulatory approval, service-level commitment, or guarantee that any system is free from risk. Customer-specific commitments, if any, are governed only by the applicable signed agreement.