ncdLabs
Vulnerability management

Vulnerability management policy

NorthCoast DevOps LLC (ncdLabs) maintains a vulnerability management process covering application code, dependencies, and internet-facing services we operate.

Sources of findings

Triage

The ncdLabs on-call representative (or designee) triages new findings for:

Remediation targets

These are internal targets, not contractual SLAs unless a customer agreement says otherwise. False positives and accepted risks are documented with rationale.

Verification

Fixes are verified by re-running relevant automated checks and, when needed, targeted manual validation in a non-production environment before production deploy.

Reporting a vulnerability

Email security@ncdlabs.com with steps to reproduce, affected product or URL, and impact assessment if known. Please avoid public disclosure until we confirm a fix or mitigation. We do not operate a paid bug bounty unless separately announced.

Last updated: September 27, 2026

NorthCoast DevOps LLC (ncdLabs)