Skip to content

Security: dsguard/community

SECURITY.md

Security Policy

DSGuard is a database security product. We take vulnerability reports seriously.

Reporting a vulnerability

Do not open a public issue for security problems.

Report privately via GitHub: Security → Report a vulnerability

Only the DSGuard team can see these reports.

What to include

  • DSGuard version
  • Affected component (e.g. PostgreSQL proxy, masking engine, Web UI)
  • Vulnerability type (e.g. authentication bypass, privilege escalation, injection)
  • Description and impact
  • Steps to reproduce / proof of concept
  • Suggested mitigation, if any

Please redact credentials, tokens and real customer data.

Our commitment

Stage Target
Acknowledgement within 2 business days
Initial assessment within 7 days
Fix or mitigation plan within 90 days

We will keep you informed throughout, credit you in the advisory if you wish, and publish a GitHub Security Advisory (GHSA) when the fix is released.

Safe harbour

We will not pursue legal action against researchers who act in good faith, avoid privacy violations and data destruction, and give us reasonable time to remediate before public disclosure.

There aren't any published security advisories