1. Key Security Controls
DOTCHATER LLC enforces rigorous technical, administrative, and physical safeguards across all deployed applications, cloud infrastructure, and partner integrations:
- Data Protection & Encryption: All partner and application data transmitted across public networks is encrypted using TLS 1.3 protocol. Stored data, database snapshots, and persistent storage are encrypted at rest using industry-standard AES-256 encryption.
- Access Control & Authentication: Strict Principle of Least Privilege (PoLP) and Role-Based Access Control (RBAC) govern all internal developer and production environment access. Multi-Factor Authentication (MFA) is mandatory for all team access to cloud portals, code repositories, and production servers.
- System Monitoring & Audit Logging: Continuous automated logging monitors system calls, API requests, authentication attempts, and network configuration changes. Centralized, tamper-proof logs are audited regularly.
- Network & Environment Isolation: Production workloads run within Virtual Private Clouds (VPC) segregated from non-production staging and development environments. Public internet ingress is restricted via Web Application Firewalls (WAF).
2. Vulnerability Management Process
We maintain an active vulnerability identification, triage, and remediation lifecycle:
- Automated Scanning: CI/CD pipelines run automated Static Application Security Testing (SAST) and software composition analysis (SCA) on every code pull request to flag vulnerable dependencies prior to production deployment.
- Vulnerability Triage: Reported vulnerabilities are categorized according to CVSS v3.1 severity scores:
- Critical (CVSS 9.0 - 10.0): Remediation targeted within 24 hours.
- High (CVSS 7.0 - 8.9): Remediation targeted within 72 hours.
- Medium / Low (CVSS < 7.0): Remediation scheduled within the next sprint release cycle (≤ 14 days).
- Vulnerability Reporting (Responsible Disclosure): External security researchers and marketplace partners can report potential security issues directly to our dedicated security team at security@dotchater.com. We acknowledge all submissions within 24 hours.
3. Security Incident Response & Handling
In the event of a suspected or confirmed security incident or data anomaly, DOTCHATER LLC follows an established Incident Response Framework:
- Detection & Triage: Automated real-time alerts trigger immediate technical review by our on-call engineering leads upon detecting unusual activity or unauthorized system access.
- Containment & Eradication: Compromised instances or credentials are isolated within minutes to contain potential lateral movement while root cause investigation and patch deployment occur.
- Partner & Customer Notification: If a security incident impacts partner data or platform integration systems, affected partners and users will be notified without undue delay, and no later than 24 to 72 hours following confirmation of the breach. Notifications detail the nature of the incident, affected data scopes, and mitigation steps taken.
- Post-Mortem & Remediation: Following incident resolution, a comprehensive post-incident analysis is conducted to update security policies and prevent reoccurrence.
4. Contact & Compliance Inquiries
For questions regarding this Partner Security Policy, vendor risk assessments, or security reporting, please contact our Security Office:
security@dotchater.com
DOTCHATER LLC — Security & Trust Department