Skip to main content
DBIS

Security & trust

Security reporting and institutional trust anchors

DBIS publishes security reporting channels, handling expectations, and cryptographic trust materials for member institutions, researchers, and counterparties.

Reporting workflow

  1. 1. Report a vulnerability or trust issue through the protected reporting workflow or the designated security mailbox.
  2. 2. Include affected system, impact, reproduction notes, and whether member or shared infrastructure is involved.
  3. 3. DBIS acknowledges critical submissions on a same-business-day basis and coordinates remediation windows with impacted operators.
  4. 4. Advisories are published after containment, validation, and institutional approval.

Preferred route

Authenticated members: use /report after Keycloak sign-in. Security mailbox: [email protected]. Whistleblower matters: [email protected] or the whistleblower intake page.

Trust anchors

  • Machine-readable trust metadata/.well-known/trust.json— endpoints, contract addresses, entity registrations
  • Governance body definitions/governance.json— councils, officers, accountability
  • Policy specifications/policy.json— settlement tokens, gold tokens, contract addresses
  • Key continuity statementsPublication of signing-key rotations, compromise notices, and trust deprecations.

Security contact posture

Initial contact points are intentionally limited while institutional processes are hardened. Dedicated addresses, signed acknowledgements, and escalation ladders will be published here once the trust package is finalized.