Security & Compliance

How DEC-LLC thinks about security, disclosure, and compliance.

Every DEC-LLC appliance ships with identical security hardening at every edition. We do not paywall protection. This page explains our security posture, how to report a vulnerability responsibly, and how we approach compliance certifications.

Security posture

Reporting a vulnerability

We welcome responsible disclosure. If you have found a vulnerability in any DEC-LLC product or on dec-llc.biz infrastructure:

A /.well-known/security.txt advertises the above on every DEC-LLC web property.

Compliance certification posture

We take compliance certifications seriously — which is why we do not speculatively pursue them ahead of committed customer demand. Each certification below is a 12–24 month engagement that requires dedicated audit budget and infrastructure-under-scope. We begin that work when an enterprise customer with a certification requirement contracts with us and the certification is written into the engagement.

Under active customer evaluation we are happy to:

Roadmap — engaged when a customer commits

Certification Status Typical customer driver
SOC 2 Type IScoped; ready to engageSaaS / enterprise procurement requirement
SOC 2 Type IIFollows Type I by 12 monthsSaaS / enterprise procurement requirement
ISO 27001Scoped; ready to engageInternational enterprise procurement
CMMC Level 2Scoped; ready to engageFederal contractor / DoD supply chain
FedRAMP ModerateEvaluating — major infra + ops commitmentFederal direct deployment

Certifications require revenue to fund the audit cycle and dedicated infrastructure to hold the control boundary. We're transparent about the sequencing: revenue first, certification committed alongside the customer contracting for it, audit engagement starts at contract signing. That way the certification corresponds to a real control environment being exercised by a real customer — not a shelf document produced ahead of demand.

Security artifacts available under NDA

Request: security@dec-llc.biz