DMUT Support and Security Response Policy

Version: 2026-07-29
Status: release candidate

1. Support scope

Invitation users receive community or designated invitation-channel support without a commercial SLA. Scope includes installation, startup, updates, authorization, Global/CN model configuration, advanced tools, workflows, reproducible defects, crashes and routing of security or privacy requests.

It excludes purchasing or managing third-party model accounts, guarantees of model accuracy, unsupported plugins or modified packages, ongoing operation of customer Projects, and enterprise SSO/SCIM/private deployment/SLA services without a separate agreement.

2. Channels

  • Support email: support@localqds.com
  • Security email: security@localqds.com
  • Privacy email: privacy@localqds.com
  • Service status: https://dmut.localqds.com/status/
  • Support hours and time zone: Monday–Friday, 09:30–18:00 Asia/Shanghai, excluding PRC public holidays

Do not send invitations, API keys, tokens, customer files or unpatched vulnerability details through a public issue, group chat or screenshot.

3. Reporting a problem

Include the Global/CN distribution, DMUT and Windows versions, event time, reproduction steps, expected and actual results, redacted logs/screenshots, and whether data loss, security, cost or business interruption is involved.

4. Severity and invitation-stage targets

Severity Example Target acknowledgment
S0 Signing/private-key compromise, remotely exploitable critical issue, widespread unauthorized access Within 4 hours; incident response starts immediately
S1 Authorization bypass, material data exposure, installer supply-chain issue Within 1 business day
S2 Core function unavailable, repeated crash, authorization or device release unavailable Within 2 business days
S3 General defect, compatibility or copy issue Within 5 business days

These are invitation-stage targets, not a commercial SLA. Enterprise SLA terms require a separate contract.

5. Security reports

Include affected versions, prerequisites, minimum reproduction, impact and suggested mitigation. Do not access another person’s data, damage service, perform denial-of-service testing or publish an unpatched vulnerability.

For good-faith reports that follow this policy, we will use reasonable efforts to acknowledge, assess, remediate and coordinate disclosure.

6. Incident actions

A serious event may cause revocation of invitations, accounts, devices or keys; suspension of download, activation or update services; a mandatory security release; rotation of signing keys, token pepper or code-signing certificates; notice to affected users or authorities; and publication of recovery guidance.

7. Support data

Submit only information required to resolve the issue. Logs, diagnostics and tickets are handled under the DMUT Privacy Policy and deleted or anonymized according to the published period.