NetDefend

Security

Security policy and responsible disclosure.

NetDefend is built around practical protection, clear reporting paths, and responsible handling of website and support information.

Form protections

Active safeguards

Enforced
Input validation
Form size limits
Origin checks
Honeypot fields
Rate limiting

Found an issue? Report it responsibly.

NetDefend reviews disclosure reports before anything is shared publicly.

Security approach

Clear reporting, practical controls, and careful information handling.

This policy gives clients, researchers, and visitors a safer way to report concerns without relying on public comments or informal social messages.

Security-first website handling

01

NetDefend treats the website as part of the brand's trust surface. Public forms use validation, size limits, origin checks, honeypot fields, and rate limiting to reduce common abuse.

Security controls will continue to mature as email, CRM, support ticketing, analytics, and internal admin tooling are introduced.

Private routes and safe errors

02

Private or administrative paths are not linked from public navigation and are not confirmed through public error messages.

Unexpected errors use a branded fallback that avoids stack traces, environment details, secrets, and private route information. Limited sanitized error context may be logged to support debugging.

Sensitive information boundaries

03

Do not submit passwords, MFA codes, recovery keys, API keys, private certificates, payment card data, or confidential secrets through public website forms.

If NetDefend needs sensitive technical information for a scoped engagement, it should be exchanged through an agreed secure process.

Responsible disclosure

04

If you believe you found a vulnerability affecting NetDefend systems, report it through the contact path below with enough detail to understand the issue.

Please avoid accessing, modifying, deleting, copying, or publicly disclosing data that does not belong to you. Give NetDefend reasonable time to review and respond before sharing details publicly.

This is a responsible disclosure channel, not a bug bounty programme, and it does not authorize denial-of-service testing, social engineering, spam, destructive testing, or testing against third-party systems.

What to include in a report

05

Include the affected URL or feature, a clear description of the issue, reproducible steps, browser or tooling context, approximate time observed, and your contact information.

Do not include exploit code beyond what is necessary to explain the issue, and do not attach sensitive client or third-party data.