Security

Report a Vulnerability

Confidential reporting

Report a Vulnerability

Send a complete, reproducible report to the BastionGuard Security Team. Please avoid placing undisclosed vulnerability details in public issue trackers.

Primary channel

Email the Security Team

Use the official security contact for vulnerability reports, proof-of-concept files, disclosure coordination, and researcher-credit preferences.

Email info@bastionguard.eu
Standard endpoint

security.txt

Automated security tooling can discover the BastionGuard reporting contact, policy, acknowledgment page, and canonical endpoint.

Open security.txt

Recommended report structure

Subject: [Security Report] Short vulnerability title

Reporter:
Affected product and component:
Affected versions:
Environment and package source:
Vulnerability type / CWE:
Summary:
Technical details:
Reproduction steps:
Proof of concept:
Security impact:
Preconditions and limitations:
Suggested mitigation or fix:
Preferred public credit:
Proposed disclosure date:

Handling sensitive files

Remove unrelated personal information, credentials, tokens, and production data. Use synthetic test data whenever possible. Tell us before sending unusually large files or encrypted archives so we can agree on a suitable transfer method.