Vulnerability disclosure policy
We take the security of our software and the protection of our users seriously. We welcome responsible reports of suspected vulnerabilities that help us identify security risks and improve our products. This policy explains how to submit a report and sets out our approach to assessment, remediation and coordinated disclosure.
Reporting a vulnerability
Submit reports through the Vulnerability reporting form or by email to security@busilabs.com
Reports must be based on the submitter's own investigation. Reports generated solely by LLMs or similar AI tools are not accepted. Automated submissions are not permitted.
Please include, where available:
- The affected product, version, configuration and relevant extensions or custom code.
- A description of the issue, potential security impact and any evidence of active exploitation.
- Reproduction steps and a minimal proof of concept.
- Contact details for follow-up.
Do not send live credentials or unnecessary personal or confidential information. If sensitive evidence is needed, contact us to arrange an appropriate transfer method.
How we handle reports
We assess relevance, reproducibility and security impact, and prioritise remediation according to risk. We may request further information or coordinate with component providers. Remedies may include patches, mitigations or other corrective measures.
This policy does not promise an individual acknowledgement or reply to every report, regular status updates, or a fixed response or resolution time. We communicate as needed for investigation and coordinated disclosure.
Coordinated disclosure
We aim to notify affected partners and customers first and give them a reasonable opportunity to apply updates or mitigations before public disclosure, where this better protects users.
Please keep non-public vulnerability details and proof-of-concept material confidential until we publish an advisory or until a disclosure date agreed with us.
Security advisories and remediation guidance are published at security advisories page. Relevant report information may be shared as needed for investigation, remediation or coordinated disclosure.
Non-qualifying reports
Reports limited to the following matters do not qualify as product vulnerability reports:
- Existing CVEs: Repeat reports about CVEs already assessed for the affected product, with no new findings.
- Physical access and social engineering: Physical theft, hardware tampering, phishing or deception that does not exploit a software flaw, and requests for optional additional safeguards against these attacks.
- Deployment capacity and resource exhaustion: Resource exhaustion or unavailability caused solely by the sizing, capacity or operation of a customer- or third-party-managed environment.
- Independent software, developments and operations: Problems caused solely by software, developments or services outside our agreed supply, or by customer-selected configurations, backup arrangements or failure to meet applicable technical requirements.
- Password policy preferences: Requests to change password length, complexity, rotation or expiry rules based solely on organisational preferences.
- Public information: Information intended for unrestricted public access, and observations limited to product names, identifiers or version strings.
- Spam and abuse-prevention preferences: Requests to change spam filtering, CAPTCHA or moderation policies based solely on operational preferences.
- Prior account compromise: Actions requiring an already compromised account that remain within that account's legitimate privileges.
- Business permissions and configuration preferences: Requests for a different allocation of legitimate business permissions or different administrator-selected settings, based solely on organisational preferences.
- Authorised development and configuration features: Permitted use of scripting, extensions, automation, queries or configuration within granted privileges and the product's intended security boundaries, including code execution, data modification and resource consumption.
- Commercial licence and activation matters: Requests about licence quantities, activation, reactivation or additional operating environments, and observations limited to technical non-enforcement of commercial licence limits.
- Ordinary functional issues: Non-security errors in calculations, business rules or outputs, and requests for additional business functionality.
Testing and other terms
Test only installations and data you are legally entitled or authorised to test. Use an isolated environment where practicable and avoid disruption, unauthorised data access or other harm. Submitting a report does not authorise us to access customer or third-party systems or data.
No bounty, payment, reimbursement, reward or public credit is promised.
This policy grants no additional software, testing or access rights and creates no paid engagement, warranties, service levels or entitlements to additional services. It does not amend applicable agreements or limit mandatory obligations or existing rights, remedies and commitments.
Report a Vulnerability Securely
If you need to report a security vulnerability confidentially, please encrypt your message using our PGP key below.
How to use: Import this key into your PGP-compatible email client, encrypt your report to the email address above, and send it .
Report a Vulnerability
Thank you for contacting us.
We will review your submission as soon as possible.
Please try again later.
