Security Policy & Vulnerability Disclosure
Our technical security practices, infrastructure controls, and responsible vulnerability disclosure policy.
Last Revised: August 1, 2025
## 1. Our Commitment to Security At Northwind Studio, security is built into our software development lifecycle from day one. We employ defensive architecture across all our infrastructure, applications, and client engagements.
2. Core Security Controls - **Transport Security:** Strict HTTPS enforcement with HTTP Strict Transport Security (HSTS `max-age=63072000; includeSubDomains; preload`). - **Content Security Policy (CSP):** Strict CSP headers restricting inline script execution and unauthorized frame embedding. - **Access Control:** Multi-factor authentication (MFA) and least-privilege role-based access across all internal repositories and cloud environments. - **Continuous DevSecOps:** Automated SAST, DAST, and dependency vulnerability scanning on every code pull request.
3. Responsible Vulnerability Disclosure Program We welcome responsible security disclosures from independent researchers. If you identify a potential security vulnerability in our systems, please report it promptly following these guidelines: - Email your findings directly to [security@northwindstudio.com](mailto:security@northwindstudio.com). - Include detailed reproduction steps, proof-of-concept payloads, and affected URLs/parameters. - Allow us a reasonable timeframe (typically 72 hours for initial acknowledgment) to investigate and deploy remediation before public disclosure. - Do not engage in automated DDoS attacks, data exfiltration, or modification of live user data.
We do not pursue legal action against security researchers who discover and report vulnerabilities in good faith in accordance with this policy.