Langdock Logo

Vulnerability Disclosure Policy

An important part of Langdock's strategy for building a secure platform for our users is vulnerability reporting. We value working with the broader security research community and understand that fostering that relationship will help Langdock improve its own security posture. We take vulnerabilities very seriously regardless of source, and strongly encourage people to report security vulnerabilities privately to our engineering team before disclosing them in a public forum. Our goal is to surface vulnerabilities and resolve them privately before they can be exploited.

Our Commitment

1. In scope

We commit to investigate and address any reported issues, and request that you use the following process for the reporting of security vulnerabilities in the following products:

2. Out of Scope

Third party dependencies. This policy does not cover vulnerabilities discovered in information systems owned by third party entities. If any such vulnerabilities are identified, they should be reported directly to the vendor, in accordance with their disclosure policy.

3. We will keep all information you provide to us confidential.

4. We assure you that we will not initiate legal action against researchers who are acting in good faith and adhering to this process.

The Process

1. Report the Concern

If you have any security concerns or would like to report undisclosed security vulnerabilities in our products or services, please email us at security@langdock.com. Note that we do not accept bug reports at this address.

2. Include Details

Please provide as much information as you can about the potential vulnerability, including but not limited to the following:

Preferably, send a plain-text email for each vulnerability you are reporting.

3. Vulnerabilities in Other Open Source Projects

We incorporate software from other open source projects, and welcome vulnerability reports for those. However, you should also report those vulnerabilities directly to the affected project.

4. Use Common Sense

Please use common sense when looking for security issues with our products.

Next Steps

We will promptly investigate any reported issue. In certain cases, we may work privately with you to resolve the vulnerability. We may choose not to disclose information publicly while we investigate and mitigate any risk.

Upon validation and appropriate mitigation (if any) of the risk, we will alert affected customers, and add the CVE to the following list.