DMUT Support and Security Response Policy
Version: 2026-07-29
Status: release candidate
1. Support scope
Invitation users receive community or designated invitation-channel support without a commercial SLA. Scope includes installation, startup, updates, authorization, Global/CN model configuration, advanced tools, workflows, reproducible defects, crashes and routing of security or privacy requests.
It excludes purchasing or managing third-party model accounts, guarantees of model accuracy, unsupported plugins or modified packages, ongoing operation of customer Projects, and enterprise SSO/SCIM/private deployment/SLA services without a separate agreement.
2. Channels
- Support email:
support@localqds.com - Security email:
security@localqds.com - Privacy email:
privacy@localqds.com - Service status:
https://dmut.localqds.com/status/ - Support hours and time zone: Monday–Friday, 09:30–18:00 Asia/Shanghai, excluding PRC public holidays
Do not send invitations, API keys, tokens, customer files or unpatched vulnerability details through a public issue, group chat or screenshot.
3. Reporting a problem
Include the Global/CN distribution, DMUT and Windows versions, event time, reproduction steps, expected and actual results, redacted logs/screenshots, and whether data loss, security, cost or business interruption is involved.
4. Severity and invitation-stage targets
| Severity | Example | Target acknowledgment |
|---|---|---|
| S0 | Signing/private-key compromise, remotely exploitable critical issue, widespread unauthorized access | Within 4 hours; incident response starts immediately |
| S1 | Authorization bypass, material data exposure, installer supply-chain issue | Within 1 business day |
| S2 | Core function unavailable, repeated crash, authorization or device release unavailable | Within 2 business days |
| S3 | General defect, compatibility or copy issue | Within 5 business days |
These are invitation-stage targets, not a commercial SLA. Enterprise SLA terms require a separate contract.
5. Security reports
Include affected versions, prerequisites, minimum reproduction, impact and suggested mitigation. Do not access another person’s data, damage service, perform denial-of-service testing or publish an unpatched vulnerability.
For good-faith reports that follow this policy, we will use reasonable efforts to acknowledge, assess, remediate and coordinate disclosure.
6. Incident actions
A serious event may cause revocation of invitations, accounts, devices or keys; suspension of download, activation or update services; a mandatory security release; rotation of signing keys, token pepper or code-signing certificates; notice to affected users or authorities; and publication of recovery guidance.
7. Support data
Submit only information required to resolve the issue. Logs, diagnostics and tickets are handled under the DMUT Privacy Policy and deleted or anonymized according to the published period.