🛡️ Vulnerability Disclosure Policy
Responsible disclosureIf you believe you have found a security vulnerability in a D.I Limited website or service, please report it responsibly.
How to report
- Email: security@diltd.vn
- Contact page: /contact/
What to include
- A clear description of the issue and affected URL(s)
- Steps to reproduce (as safely as possible)
- Impact assessment (what could be exploited / accessed)
- Any relevant logs, screenshots, or proof-of-concept details (only if needed)
- Your preferred contact information for follow-up
Scope
In scope: websites and services under the diltd.com.vn or diltd.vn domains.
Out of scope: third-party services we do not control.
Safe testing rules
- Do not perform denial-of-service (DoS) or disruptive testing
- Do not access, modify, or delete data that is not your own
- Do not use social engineering or physical attacks
- Stop testing immediately if you believe you may impact systems or users
What we commit to
- We will acknowledge receipt of your report and may request clarifications
- We will work to validate and remediate confirmed issues
- With your permission, we can credit you on our acknowledgments page
Encrypted reports: if you want to encrypt sensitive details, please use the public key published in
/.well-known/security.txt.
Security acknowledgments: /security/acknowledgments/