Report a vulnerability.
How to report, what to expect, and what is safe to test.
How to report
Email [email protected]. There is no PGP key yet. If you need encrypted transport for a report, say so in a first message and we will arrange it before you send details. Include the module version, a reproduction, and impact as you understand it.
What to expect
Acknowledgement within one business day. Status updates every five business days until it is closed. Fix or mitigation target: seven days for critical or high severity, thirty days otherwise, or the next release if that comes sooner. Where a full fix needs longer, we publish a mitigation inside the same window and tell you why.
In scope
The SpnManager module and C# engine, this website, the evidence-pack signing process.
Out of scope
Azure Marketplace and AWS Marketplace platforms (report to them). Your own Active Directory. Denial of service against this website.
Safe harbour
Research in good faith and we will not pursue legal action or ask anyone else to. Good faith means testing only against systems you own or are authorised to test, not accessing or altering anyone else’s data, not degrading a service, and giving us a reasonable chance to fix the problem before you publish. If you are unsure whether something is in scope, ask first — we would rather answer the question than argue about it afterwards.
Credit
Reporters are credited in the release notes if they wish. We do not pay cash bounties. We will credit you by name if you want the credit, and we will give you a Professional licence.