Security

Vulnerability Disclosure Policy

Responsible disclosure

Vulnerability Disclosure Policy

This policy explains how to report a suspected BastionGuard vulnerability and how the BastionGuard Security Team handles coordinated disclosure.

Security contact

Send reports to info@bastionguard.eu. Include enough technical detail for us to reproduce and assess the issue.

Scope

This policy covers BastionGuard releases, source code, official packages, repositories, websites, APIs, and infrastructure maintained by the BastionGuard Security Team. Third-party software, distribution infrastructure not controlled by BastionGuard, social engineering, denial-of-service testing, and physical attacks are outside the scope unless explicitly authorized.

What to include

  • A clear description of the vulnerability and affected component.
  • Affected versions, operating system, package source, and relevant configuration.
  • Reproduction steps, proof of concept, logs, traces, screenshots, or a minimal test case.
  • Expected and observed behavior, security impact, and known preconditions.
  • Suggested remediation or mitigations, when available.
  • Your preferred public credit and any disclosure deadline you are proposing.

Response targets

01

Acknowledgment: we aim to acknowledge a complete report within 3 business days.

02

Initial assessment: we aim to provide an initial scope and validity assessment within 7 business days.

03

Remediation: timelines depend on severity, complexity, supported releases, package distribution, and the availability of a safe fix.

04

Publication: we coordinate advisory publication, researcher credit, release availability, and CVE assignment when appropriate.

Coordinated disclosure

Please keep technical details confidential until a fix or agreed mitigation is available and a coordinated publication date has been reached. We will keep you informed of material progress and will not intentionally delay disclosure without a concrete security reason.

Researcher credit

We credit researchers in the public advisory and release communications when they authorize publication of their name or handle. Anonymous reports are also accepted. We do not publish personal contact details without explicit permission.

Safe-harbor statement

When research is conducted in good faith, stays within this policy, avoids privacy violations and service disruption, and gives us a reasonable opportunity to remediate the issue, the BastionGuard Security Team will treat the activity as authorized security research and will not initiate legal action solely because of that research.

Prohibited activity

  • Accessing, altering, retaining, or disclosing data that does not belong to you.
  • Disrupting production systems, repositories, downloads, or other users.
  • Using destructive payloads, persistence, malware, ransomware, or automated high-volume scanning.
  • Publishing exploit details before a coordinated disclosure date without first making a good-faith attempt to work with us.

Rewards

BastionGuard does not currently operate a paid bug-bounty program. Public acknowledgment, advisory credit, and CVE credit may be provided when appropriate and authorized by the researcher.