Security
Report a vulnerability
Email security@dxcslabs.com (also published at /.well-known/security.txt). Please include what you found and why it matters, steps to reproduce, and the affected component (platform, PHP agent or WordPress plugin) and version.
- We acknowledge within 2 business days and give an initial assessment within 5.
- Test only against your own account. Do not access other customers' data, degrade the service, or use social engineering or physical attacks.
- Give us a reasonable window to fix before disclosure. We credit reporters who want it, and we will not pursue anyone who follows these rules in good faith.
How the platform is protected
Accounts
- Passwords: at least 12 characters with mixed case and numbers, checked against known breaches using a k-anonymity range query (only 5 characters of a hash leave our server); stored as bcrypt hashes.
- Two-factor authentication (TOTP) and passkeys (WebAuthn, phishing-resistant); companies can require a second factor for everyone.
- Rate limits per account and per address, account lockout after repeated failures, re-authentication for sensitive changes, and a visible history of sign-ins and sessions you can revoke.
Data
- TLS everywhere with HSTS. Secrets (agent keys, 2FA seeds, repository tokens, webhook addresses) are encrypted at rest; API tokens are stored only as hashes.
- Every company's data is isolated and every request is authorised against it.
- Retention limits are enforced automatically every night — see the privacy notice.
The application
- A strict Content Security Policy with per-request nonces, no third-party scripts, styles or fonts, framing disabled, and the other modern security headers on every response.
- Every outbound request to an address a customer supplied (uptime checks, webhooks) is resolved, checked against private and internal ranges, and pinned — so the platform cannot be turned against internal networks.
- Security events — failed sign-ins, failed second factors, refused requests — are logged, and unusual volumes alert our administrators.
- Errors never show internal details; dependencies are audited before each release.
The agent
- Agent traffic is signed (HMAC-SHA256) with a per-site secret, timestamped and nonce-checked against replay.
- Updates are signed with a key that is not stored on our servers; agents refuse anything unsigned.
- The platform can only ask the agent to run a fixed list of operations — never arbitrary code — and the agent enforces its own copy of that list.
If something goes wrong
We keep a breach register and a written response procedure. Personal-data breaches are reported to the Data Protection Board of India and to the people affected without delay, with a detailed report to the Board within 72 hours; customers are told within 24 hours about anything affecting their visitors' data (DPA §6).