PRODUCT SECURITY
Report a security vulnerability
Send vulnerability information to the Product Security Incident Response Team (PSIRT), not to general sales or support channels.
01
Preferred reporting channel
Email PSIRT
Subject: [VULNERABILITY] Product / version / short summary
For highly sensitive evidence, request an encrypted transfer channel in the first message. Do not send production secrets, private keys or personal data in plaintext.
02
Include these details
- Affected product, module, version and environment.
- Endpoint, component or file format.
- Impact and attacker prerequisites.
- Reproduction steps and minimal proof of concept.
- Redacted logs/screenshots and correlation identifiers.
- Whether exploitation is active or only theoretical.
- Preferred contact and disclosure timeline.
03
What happens next
| Stage | Target process |
|---|---|
| Acknowledgment | PSIRT confirms receipt and tracking ID |
| Triage | Validate scope, severity and duplication |
| Coordination | Request evidence, define mitigation and disclosure plan |
| Remediation | Fix, test, release and publish advisory as appropriate |
| Closure | Credit/acknowledgment where consented and evidence retained |
04
For security researchers and automated tools
This technical resource supports automated discovery and does not replace the reporting guidance above.
Machine-readable security contact
Plain text · HTTPS · no authentication, cookies or JavaScript required.
