ThreatDown Coordinated Vulnerability Disclosure

Overview

ThreatDown welcomes and encourages independent researchers to report vulnerabilities in our products to us. It is the objective of this Coordinated Vulnerability Disclosure (CVD) program to work with leading researchers in making our products more secure and help protect our users and services.

The CVD program incentivizes external researchers who work with us responsibly by promoting an open communication channel with our security division, awarding bug bounties and duly crediting the effort from leading researchers.

By submitting a security bug or vulnerability to ThreatDown, you acknowledge that you have read and agreed to the Program Guidelines.

ThreatDown publishes CVEs details to the CVE List.

Reporting a security vulnerability

ThreatDown offers a responsible disclosure program together with a public bug bounty program.

ThreatDown encourages security researchers to submit vulnerability reports for any ThreatDown website, product or service, in an encrypted format to product-security@threatdown.com. Our PGP key can be found HERE.

ThreatDown also runs a public bug bounty program on the HackerOne platform for specific targets in scope. If you wish to participate, refer to the program page for more details.

The ThreatDown application security team will acknowledge receipt of your report, validate and reproduce the issue together with the product development team. Additional help and collaboration might be requested to the security researcher to go through the reproduction steps and make sure the potential security impact is confirmed.