🛡️ Vulnerability Disclosure Policy

Responsible disclosure

If you believe you have found a security vulnerability in a D.I Limited website or service, please report it responsibly.


How to report

What to include

  • A clear description of the issue and affected URL(s)
  • Steps to reproduce (as safely as possible)
  • Impact assessment (what could be exploited / accessed)
  • Any relevant logs, screenshots, or proof-of-concept details (only if needed)
  • Your preferred contact information for follow-up

Scope

In scope: websites and services under the diltd.com.vn or diltd.vn domains.

Out of scope: third-party services we do not control.

Safe testing rules

  • Do not perform denial-of-service (DoS) or disruptive testing
  • Do not access, modify, or delete data that is not your own
  • Do not use social engineering or physical attacks
  • Stop testing immediately if you believe you may impact systems or users

What we commit to

  • We will acknowledge receipt of your report and may request clarifications
  • We will work to validate and remediate confirmed issues
  • With your permission, we can credit you on our acknowledgments page