Security Statement
Version 1.0Current Official ReleaseEffective Date: 2026-07-31 · Last Updated: 2026-07-31
Security Statement
Effective Date: July 31, 2026 Last Updated: July 31, 2026 Version: 1.0
Our Approach to Security
Dominus Energy Group LLC treats the security of Donnas-Bandwidth-Booster™ as a foundational requirement, not an afterthought. This Security Statement summarizes, at a public-facing level, the practices we have implemented. For a more detailed technical breakdown of authentication, encryption, and access control, see the Security & Privacy Overview.
Authentication
- User and administrator passwords are hashed using bcrypt; we do not
store passwords in plain text.
- Administrator accounts require multi-factor authentication (TOTP-based)
in addition to a password, and are subject to lockout after repeated failed sign-in attempts.
- Sessions use short-lived access tokens paired with revocable refresh
tokens, so access can be cut off promptly when needed.
Encryption
- Data in transit is protected using TLS 1.3.
- Sensitive free-text fields (such as diagnostic report content) are
encrypted at rest using AES-256-GCM.
Access Control
- Administrative functions require an authenticated account with the
`admin` role.
- Every administrative action is recorded in an append-only audit log.
- Access to production systems and data is restricted on a
need-to-know basis.
Account Recovery
Administrator password resets require out-of-band verification of a recovery contact and force the creation of a new password on next login, reducing the risk of account takeover through a single compromised channel.
Current State of Our Infrastructure
In the interest of transparency, we disclose the current state of our infrastructure honestly rather than describing aspirational capabilities as if they were already in place:
- Security practices described above are implemented in the codebase
and services that make up Donnas-Bandwidth-Booster™.
- As features and infrastructure continue to roll out toward public
availability, some backend services and monitoring capabilities are still being finalized. Where a specific capability (for example, automated backups) is not yet configured, we say so directly — see, for example, the Backups section of the Data Retention Policy.
Vulnerability Reporting
We welcome reports from security researchers conducted in good faith and within the bounds of an approved security research or bug-bounty engagement, consistent with the exception described in our Acceptable Use Policy. If you believe you have found a security vulnerability, please report it using the Security Vulnerability Reporting contact in Contact Information. See also our Incident Response & Security Notification Policy for what happens after a report is received.
What We Do Not Do
Consistent with our Privacy Policy, we do not sell your data, and we do not collect precise location, browsing history, or other-app usage data.
Changes to This Statement
We may update this Security Statement as our security practices evolve. Material changes will be reflected in the "Last Updated" date above.
Contact
Security questions or reports can be directed to us using the Security Vulnerability Reporting contact in Contact Information.