Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Knowledge Center
  3. Announcements

Guardsix coordinated vulnerability disclosure policy

Avatar Ekraj Pandit
September 11, 2026 03:47
Follow

We are committed to the security of our products and services. We value the work of security researchers, customers, and partners who help us identify and responsibly report security vulnerabilities. We welcome reports made in good faith, and we work with reporters to investigate, remediate, and coordinate the disclosure of confirmed vulnerabilities.

This policy explains how to report security vulnerabilities, what we ask of researchers, and what we commit to in return.

Scope

This policy applies to Guardsix products, services, and systems that we own, operate, or maintain, including:

  • Guardsix products and the supported services
  • Guardsix-owned websites, domains, and subdomains (*.guardsix.com, *.logpoint.com)

The following are outside this policy, and we ask that you do not test them:

  • Third-party products, services, platforms, or infrastructure not owned or operated by Guardsix.
  • Unsupported or end-of-life Guardsix products.
  • Corporate IT systems, employee devices, office facilities, and internal business applications.
  • Social engineering of Guardsix employees, customers, or partners.
  • Physical security testing.
  • Denial-of-service (DoS), distributed denial-of-service (DDoS), or other testing intended to impair the availability of production services.
  • Spam, phishing, or other abusive activity.

The following are generally not considered security vulnerabilities unless accompanied by demonstrable security impact:

Finding Treated as a vulnerability when
Missing HTTP security headers You can show exploitable impact
Self-XSS You can show impact on another account
Version or banner disclosure The disclosed detail enables a specific attack
Best-practice recommendations An exploitable weakness is demonstrated
Vulnerabilities in third-party software There is Guardsix-specific impact

 

Rules of engagement

When researching a vulnerability under this policy:

  • Act in good faith and avoid any activity that could harm users, data, or the availability of a service.
  • Only interact with accounts and data that belong to you, or for which you have explicit permission.
  • Stop immediately and contact us if you encounter personal data, credentials, or other sensitive information. Do not access, copy, modify, or retain it.
  • Do not establish persistent access, install malware, or create backdoors.
  • Avoid actions that could degrade or disrupt production services.
  • Keep vulnerability details confidential until we have agreed co-ordinated disclosure with you.

How to report

Send your report to g6security@guardsix.com.

Include as much of the following as you can:

  • The affected product and version.
  • A clear description of the vulnerability and its potential impact.
  • Steps to reproduce it, and a proof of concept where possible.
  • Any suggested mitigation, and how you would like to be credited.

What you can expect from us

We aim to:

  • Acknowledge receipt of vulnerability reports within two business days.
  • Complete an initial assessment within five business days.
  • Validate reported vulnerabilities and assess their severity using industry-standard methodologies such as CVSS.
  • Keep you informed of significant progress throughout the investigation.
  • Develop and distribute a fix or mitigation as appropriate.
  • Request or coordinate the assignment of a CVE identifier where appropriate.
  • Recognize your contribution, with your consent.

Some investigations or fixes take longer, because of technical complexity or product release schedules. Where that happens, we will tell you where things stand and what timeline to expect.

Coordinated disclosure

We support coordinated vulnerability disclosure. We ask you to keep vulnerability details confidential until:

  • a fix or mitigation has been released; or
  • we agree with you that disclosure is appropriate.

Where remediation requires an extended period, we will work with the reporter to agree on a reasonable disclosure timeline.

If a vulnerability is already publicly known or is being actively exploited, we may publish a limited security advisory to help customers reduce risk while withholding technical details until a fix or effective mitigation is available.

 We publish security advisories on the Guardsix Product Security page. An advisory typically includes:

  • affected products and versions;
  • severity and impact;
  • CVE identifier (where applicable);
  • remediation guidance; and
  • acknowledgements to the reporting researcher (with consent).

Safe harbour

We support responsible security research conducted in accordance with this policy.

Guardsix will not initiate or support legal action against individuals who:

  • act in good faith;
  • comply with this policy;
  • avoid violating the privacy of others;
  • avoid disrupting services or degrading system availability;
  • do not exploit vulnerabilities beyond what is necessary to demonstrate their existence; and
  • promptly report discovered vulnerabilities to Guardsix.

Activities conducted in accordance with this policy are considered authorised by Guardsix.

Nothing in this policy authorises actions that violate applicable law or the rights of third parties.

Recognition

With the reporter's consent, we will acknowledge your contribution in the associated security advisory.

Guardsix does not currently operate a paid bug bounty program.  We welcome responsible vulnerability reports, and no financial reward should be expected unless we state otherwise.

Contact

For vulnerability reports or questions regarding this policy, contact: g6security@guardsix.com.

Comments

Article is closed for comments.

Related articles

  • XXE injection in Process Eval
  • Guardsix Security Advisory: Response to Copy Fail and Dirty Frag Vulnerability
Was this article helpful? 0 out of 0 found this helpful
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.