7-Day Free Trial · From $15/month
DME Logo

Security & Responsible Disclosure

DME Technologies LLC takes the security of our platform and the privacy of our customers seriously. This page outlines the security measures we have in place and the process for reporting security vulnerabilities.

Last Updated: May 15, 2026

Our Security Practices

  • Encryption in transit: All traffic to and from dmebcard.com is encrypted using TLS 1.2 or higher.
  • Encryption at rest: Data is stored on SOC 2 compliant infrastructure with encryption at rest.
  • PCI-DSS payments: All payment data is processed by Stripe, a PCI-DSS Level 1 certified provider. We never store full card numbers on our servers.
  • Access controls: Role-based access control and least-privilege principles for staff access to production data.
  • Monitoring: Continuous application error monitoring via Sentry and audit logs for sensitive admin actions.
  • Backups: Regular automated backups with disaster recovery procedures.

Responsible Disclosure Program

We welcome reports from security researchers. If you believe you have found a security vulnerability in our service, please report it to us privately so we can address it before public disclosure.

How to report

Email a detailed report to office@dmebcard.com with the subject line "Security Vulnerability Report".

Please include:

  • A clear description of the vulnerability
  • Steps to reproduce (proof-of-concept if possible)
  • The potential impact
  • Your name and contact information (optional but appreciated)

Our commitment

  • We will acknowledge your report within 5 business days.
  • We will provide an estimated timeline for a fix within 15 business days.
  • We will not pursue legal action against good-faith researchers who follow this policy.
  • With your permission, we'll publicly credit you once the issue is resolved.

Scope & rules

Please do:

  • Test only with your own accounts or with explicit permission
  • Give us reasonable time to respond before public disclosure
  • Make a good-faith effort to avoid privacy violations and service disruption

Please do not:

  • Access, modify, or delete data belonging to other users
  • Perform denial-of-service (DoS) or spam testing
  • Use social engineering against our staff or customers
  • Test physical security of our offices or facilities

Infrastructure

Our application runs on Base44's SOC 2 compliant infrastructure in the United States. For a full list of sub-processors handling your data, see our Privacy Policy.

Contact

For any security-related concerns, contact us at office@dmebcard.com.

Special OfferFrom $15/mo - 7-day trial
15:00