Responsible vulnerability reporting for ROMA Security™ and DemeWebSolutions commercial software.
Security contact
Report security vulnerabilities to CustomerCare@demewebsolutions.com with the subject line "Security Report". Include affected product, version, reproduction steps, and impact assessment when possible.
Responsible disclosure
We ask researchers to provide reasonable time to investigate and remediate issues before public disclosure. Coordinated disclosure helps protect customers while improving product security.
Safe harbor
When you act in good faith, comply with this policy, avoid privacy violations and service disruption, and report issues promptly, we will not pursue legal action for authorized security research directed at our products and platform.
Out of scope
- Social engineering or physical attacks
- Denial-of-service testing against production infrastructure
- Issues in third-party services outside our control
PGP key (future)
An encrypted reporting key will be published here when available for sensitive submissions.