Vulnerability Disclosure Policy

Outpost24 is committed to addressing security vulnerabilities in our products and services. We take reasonable steps to minimize customer risk and provide vulnerability fixes or mitigations where appropriate.

Outpost24’s vulnerability handling process is informed by Coordinated Vulnerability Disclosure principles, including ISO/IEC 29147.

While we appreciate automated and AI-assisted scanning efforts, we ask that all reports be manually validated to confirm technical impact before submission.

Reporting a vulnerability

If you believe you have discovered a vulnerability in a Outpost24 product, service, or infrastructure, please email a high-level description of your findings to security@outpost24.com. You may encrypt your report using our PGP key to help protect sensitive information in transit.

Please do not exploit the vulnerability beyond what is necessary to demonstrate its existence or reveal the issue publicly until Outpost24 has had reasonable time to investigate and, where appropriate, provide remediation or mitigation.

To expedite verification and handling of the finding, please provide the following information in the initial communication:

  • Your preferred contact information
  • Product name, version number, IP address, or the URL of the affected system
  • Date the vulnerability was observed
  • Description of the vulnerability and its potential security impact
  • Instructions to reproduce the vulnerability
  • Relevant proof-of-concept code, screenshots, logs, or other supporting information, where available

Reports must contain sufficient information for Outpost24 to reproduce and assess the reported issue. Reports consisting only of automated scanner output, without manual validation, reproducible steps, and a description of the security impact, may be closed without further response.

Messages and reports we may not process

Messages that do not concern a potential undisclosed security vulnerability in a Outpost24 product, service, or infrastructure may be closed without response.

Do not send lists of leaked or exposed passwords, credentials, or breach data affecting Outpost24 customers when the exposure did not result from a vulnerability in a Outpost24 product. Such submissions are not treated as vulnerability reports and may be closed without response.

If you believe that a vulnerability in a Outpost24 product caused credentials to be exposed, report the vulnerability and explain how it caused the exposure. Do not include passwords, credentials, or other unnecessary personal data in the report.

Prohibited security research

Please note that we do not permit the following types of security research:

  • Actions that may negatively affect Outpost24 products or their users, such as spam, denial-of-service attacks, brute-force attacks, or high-volume automated scanning
  • Exploiting a vulnerability beyond what is necessary to demonstrate its existence
  • Accessing any account or data that does not belong to you
  • Accessing or attempting to access systems, accounts, or data that you are not authorized to access
  • Corrupting or otherwise damaging any data that does not belong to you
  • Social engineering
  • Violating any laws or breaching any agreements in order to discover vulnerabilities

Mitigation and remediation

Outpost24 will assess reports based on factors including validity, reproducibility, scope, severity, exploitability, and demonstrated real-world security impact.

If a report is confirmed valid and requires action, Outpost24 will determine an appropriate remediation or mitigation and prioritize the issue according to risk and customer impact. Outpost24 does not commit to a particular remediation method or resolution date.

Reports may be closed without further response if they concern previously known or duplicate issues, are invalid or not reproducible, fall outside the scope of this policy, are insufficiently documented, or do not demonstrate meaningful security impact. Reports describing only theoretical risk, automated findings, or deviations from security best practices without demonstrated exploitability and impact may be treated as informational.

Outpost24 may coordinate public disclosure with the reporter where appropriate. The timing and content of any public communication remain at the discretion of Outpost24.

What to expect

  • We aim to acknowledge receipt of messages that appear to report a potential vulnerability within three business days. An acknowledgment does not mean that the report has been validated or accepted.
  • We may request additional information where necessary to reproduce or assess the reported issue.
  • If you conduct and report security research in good faith and make a reasonable effort to comply with this policy, Outpost24 does not intend to initiate legal action against you regarding that research.
  • We will treat your report as confidential, except where disclosure is necessary to investigate or address the report, administer or process a reward, or comply with applicable law. We will not otherwise pass your personal details to third parties without your permission.
  • For confirmed and material vulnerabilities, we may provide progress updates, notify you when the issue has been addressed, or coordinate public disclosure.
  • If we publish information concerning the reported vulnerability, we may credit the reporter with their consent and at the discretion of Outpost24.

Acknowledgment of a report does not constitute acceptance of the report or a commitment to remediation, disclosure, attribution, or a reward.

Reward

Reward eligibility is assessed on a case-by-case basis, and all reward decisions are made at Outpost24’s sole discretion.

Our ability to process a reward payment depends on several factors, including your country of residence and the successful completion of all required payment, identity, and compliance checks. We may request additional information or documentation to comply with applicable laws, sanctions, banking requirements, or other international restrictions.

Payments involving countries, territories, individuals, entities, or financial institutions subject to such restrictions may require additional checks or may not be possible to process. Accordingly, Outpost24 does not guarantee that reward payments can be processed in every country or circumstance.