Security response
Report vulnerabilities, suspicious installers or user-impacting security incidents to security@localqds.com. Reports may be sent at any time and are prioritized by risk.
How to report
Use a subject such as [Security] Summary and include affected versions, prerequisites, a minimal reproduction, impact and proposed mitigation. The initial response target for a critical security incident is within four hours; this is not a guaranteed repair time or compensation promise.
Do not send API keys, passwords, full device fingerprints, state secrets, unrelated personal information or unredacted Project files. Do not access another person's data, damage the service, perform denial-of-service or social-engineering tests, or disclose exploitable detail before remediation.
What happens next
We acknowledge the report, triage it, coordinate mitigation and remediation, and may recognize a contributor. This policy is not a paid bug-bounty promise unless separately agreed in writing.
For a significant user-facing event, we use the service status page, email or product notice to share impact, mitigation and recovery progress. Personal-information incidents follow the Privacy Policy and applicable law.
Security updates
Security updates are delivered through DMUT's own update service. The client verifies channel, version, signature and SHA-256; install only signed versions listed on the official website or in an authorization email. For ordinary installation and update questions, use Product support.