How Do I Report a Vulnerability?
This guide explains how to report a vulnerability in a Brainboxes product when there is no evidence it has been exploited e.g. one identified through independent security research, code review, or routine testing.
If a vulnerability is being actively exploited, please follow our guide on reporting an actively exploited vulnerability instead, as that follows a faster, time-critical process.
How to report
Send your report to our dedicated security inbox:
- Email: [email protected]
- Encrypted email: use our PGP key if you'd like to encrypt sensitive details
What we need to know
- The affected product model(s) and firmware/software version(s)
- A description of the vulnerability and its potential impact
- Your contact details, so we can follow up
What we'll ask for
If you haven't already provided them, we'll ask you for the following as we investigate:
- Steps to reproduce the issue, or a proof of concept
- Any suggested mitigation
- Whether you'd like to be credited when we publish a fix
What happens next
- We'll acknowledge receipt of your report.
- Our team will investigate and validate the vulnerability, and assess its severity.
- We'll keep you updated as we work on a fix or mitigation, and let you know once one is available.
Coordinated disclosure
We ask that you give us a reasonable opportunity to investigate and address the issue before disclosing it publicly. We're happy to discuss a disclosure timeline with you as part of the process.