Vulnerability management policy
NorthCoast DevOps LLC (ncdLabs) maintains a vulnerability management process covering application code, dependencies, and internet-facing services we operate.
Sources of findings
- Static analysis (SAST) — language and framework rules (for example Semgrep) on product repositories, including CI where configured.
- Dynamic analysis (DAST) — baseline scans of staging or equivalent environments (for example OWASP ZAP) before or after release when configured.
- Dependency alerts — lockfile and package advisory tooling where enabled on repositories.
- External reports — coordinated disclosure to security@ncdlabs.com.
- Operational discovery — issues found during support, monitoring, or customer engagements.
Triage
The ncdLabs on-call representative (or designee) triages new findings for:
- Exploitability and blast radius in our deployments
- Whether customer data or credentials could be affected
- Whether a temporary mitigation (config, WAF rule, feature disable) is available
Remediation targets
- Critical (actively exploitable with high impact): mitigate immediately; aim to ship a fix within 7 days.
- High: aim to remediate within 30 days.
- Medium / Low: schedule into normal engineering work; revisit if risk increases.
These are internal targets, not contractual SLAs unless a customer agreement says otherwise. False positives and accepted risks are documented with rationale.
Verification
Fixes are verified by re-running relevant automated checks and, when needed, targeted manual validation in a non-production environment before production deploy.
Reporting a vulnerability
Email security@ncdlabs.com with steps to reproduce, affected product or URL, and impact assessment if known. Please avoid public disclosure until we confirm a fix or mitigation. We do not operate a paid bug bounty unless separately announced.