Guardsix coordinated vulnerability disclosure policy
We are committed to the security of our products and services. We value the work of security researchers, customers, and partners who help us identify and responsibly report security vulnerabilities. We welcome reports made in good faith, and we work with reporters to investigate, remediate, and coordinate the disclosure of confirmed vulnerabilities.
This policy explains how to report security vulnerabilities, what we ask of researchers, and what we commit to in return.
Scope
This policy applies to Guardsix products, services, and systems that we own, operate, or maintain, including:
- Guardsix products and the supported services
- Guardsix-owned websites, domains, and subdomains (*.guardsix.com, *.logpoint.com)
The following are outside this policy, and we ask that you do not test them:
- Third-party products, services, platforms, or infrastructure not owned or operated by Guardsix.
- Unsupported or end-of-life Guardsix products.
- Corporate IT systems, employee devices, office facilities, and internal business applications.
- Social engineering of Guardsix employees, customers, or partners.
- Physical security testing.
- Denial-of-service (DoS), distributed denial-of-service (DDoS), or other testing intended to impair the availability of production services.
- Spam, phishing, or other abusive activity.
The following are generally not considered security vulnerabilities unless accompanied by demonstrable security impact:
| Finding | Treated as a vulnerability when |
| Missing HTTP security headers | You can show exploitable impact |
| Self-XSS | You can show impact on another account |
| Version or banner disclosure | The disclosed detail enables a specific attack |
| Best-practice recommendations | An exploitable weakness is demonstrated |
| Vulnerabilities in third-party software | There is Guardsix-specific impact |
Rules of engagement
When researching a vulnerability under this policy:
- Act in good faith and avoid any activity that could harm users, data, or the availability of a service.
- Only interact with accounts and data that belong to you, or for which you have explicit permission.
- Stop immediately and contact us if you encounter personal data, credentials, or other sensitive information. Do not access, copy, modify, or retain it.
- Do not establish persistent access, install malware, or create backdoors.
- Avoid actions that could degrade or disrupt production services.
- Keep vulnerability details confidential until we have agreed co-ordinated disclosure with you.
How to report
Send your report to g6security@guardsix.com.
Include as much of the following as you can:
- The affected product and version.
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce it, and a proof of concept where possible.
- Any suggested mitigation, and how you would like to be credited.
What you can expect from us
We aim to:
- Acknowledge receipt of vulnerability reports within two business days.
- Complete an initial assessment within five business days.
- Validate reported vulnerabilities and assess their severity using industry-standard methodologies such as CVSS.
- Keep you informed of significant progress throughout the investigation.
- Develop and distribute a fix or mitigation as appropriate.
- Request or coordinate the assignment of a CVE identifier where appropriate.
- Recognize your contribution, with your consent.
Some investigations or fixes take longer, because of technical complexity or product release schedules. Where that happens, we will tell you where things stand and what timeline to expect.
Coordinated disclosure
We support coordinated vulnerability disclosure. We ask you to keep vulnerability details confidential until:
- a fix or mitigation has been released; or
- we agree with you that disclosure is appropriate.
Where remediation requires an extended period, we will work with the reporter to agree on a reasonable disclosure timeline.
If a vulnerability is already publicly known or is being actively exploited, we may publish a limited security advisory to help customers reduce risk while withholding technical details until a fix or effective mitigation is available.
We publish security advisories on the Guardsix Product Security page. An advisory typically includes:
- affected products and versions;
- severity and impact;
- CVE identifier (where applicable);
- remediation guidance; and
- acknowledgements to the reporting researcher (with consent).
Safe harbour
We support responsible security research conducted in accordance with this policy.
Guardsix will not initiate or support legal action against individuals who:
- act in good faith;
- comply with this policy;
- avoid violating the privacy of others;
- avoid disrupting services or degrading system availability;
- do not exploit vulnerabilities beyond what is necessary to demonstrate their existence; and
- promptly report discovered vulnerabilities to Guardsix.
Activities conducted in accordance with this policy are considered authorised by Guardsix.
Nothing in this policy authorises actions that violate applicable law or the rights of third parties.
Recognition
With the reporter's consent, we will acknowledge your contribution in the associated security advisory.
Guardsix does not currently operate a paid bug bounty program. We welcome responsible vulnerability reports, and no financial reward should be expected unless we state otherwise.
Contact
For vulnerability reports or questions regarding this policy, contact: g6security@guardsix.com.
Comments
Article is closed for comments.