Trust & Legal
Security
This page describes high-level security practices for the public DYWYZY website. It does not disclose internal architecture, servers, ports, or private endpoints. DYWYZY does not claim to be fully secure and does not claim ISO, SOC 2, or other certifications on this page.
1. Security Principles
The corporate site is a static presentation layer. It does not embed product engines, databases, or private APIs in the browser bundle. Secrets, API keys, and internal infrastructure are out of scope for this frontend.
2. Application Security
Frontend changes are reviewed in the website repository. Optional analytics cannot load until both configuration and consent exist.
3. Authentication and Authorization
This website has no public account login. Product access control, when offered, belongs to those products.
4. Data Protection
Assistant conversations stay in the current tab. Cookie preference storage is first-party localStorage. Privacy-request forms do not automatically complete a legal process.
5. Infrastructure Security
Hosting and network controls are not published here. Internal diagrams, IPs, and ports are not disclosed.
6. Monitoring and Logging
Public monitoring and incident tooling are not described here because they are not verified as a published capability.
7. Vulnerability Management
A published vulnerability-management SLA is not claimed. Use Responsible Disclosure for suspected issues in the public website.
8. Incident Response
A formal public incident-response SLA is not published. If you believe there is a security issue, use Responsible Disclosure below.
9. Responsible Disclosure
Please report suspected security issues in the public website or DYWYZY products in good faith. Do not access data that is not yours, and do not disrupt services.
There is no published bug bounty program.
10. Contact
A dedicated security mailbox is shown only when configured ([email protected]).
Responsible Disclosure
Report suspected issues in good faith. Do not request internal IPs, ports, architecture diagrams, or credentials. There is no published bug bounty.
Security contact: [email protected]
/.well-known/security.txt is published from the configured security contact.
Contact
Security contact: [email protected]
Official mailboxes appear only when they are configured. Placeholder addresses are not shown.