Security

Reporting a vulnerability

If you have found a security issue in the ForensicsGuard platform or in this website, we want to hear about it. This page explains how to tell us and what we will do.

How to report

Email support@forensicsguard.org with “Security” in the subject line. If you would prefer to exchange encrypted mail, say so in a first message without the detail and we will arrange it before you send anything sensitive.

What helps us act quickly

  • Which component is affected — Guardian, Lab Station, Mobile Sensor, or this website
  • The version, if you have it
  • What an attacker can achieve, and what access they need to start
  • Steps to reproduce, or a proof of concept
  • How you would like to be credited, or that you would prefer not to be

Please do not include

  • Case material, evidence, or personal data belonging to a deployment
  • Data obtained from a system you did not have authorisation to test

What we commit to

  • We will acknowledge your report.
  • We will tell you our assessment, including if we disagree that it is a vulnerability, and why.
  • We will keep you informed while we work on a fix.
  • We will credit you if you want to be credited.
  • We will not take legal action against you, or ask anyone else to, for security research conducted in good faith under the guidance on this page.

Coordinated disclosure

Please give us a reasonable opportunity to fix an issue before disclosing it publicly. Because deployments are on-premise and some are deliberately isolated, updates can take longer to reach every operator than they would for a cloud service — this is a practical constraint of the deployment model, not an attempt to delay you. If you have a disclosure deadline, tell us at the start and we will work to it or explain why we cannot.

Scope

In scope: the ForensicsGuard platform components, and this website. Out of scope: findings that require physical access to an appliance already in an attacker's possession, denial of service through resource exhaustion, reports generated solely by automated scanners without a demonstrated impact, and issues in third-party services we do not control.

Testing boundaries

Please only test against systems you own or have written authorisation to test. Do not test against a customer deployment. Do not access, modify or exfiltrate data that is not yours. If you access customer data accidentally, stop, tell us, and do not retain it.

Security contact

Subject line
Security
Languages
English
Updated
12 August 2026

Verifying our software

If you are examining a deployment's integrity rather than reporting a flaw, the verification mechanisms and public keys are documented on verification & updates and explained on Security & Trust.

No bug bounty

We do not currently operate a paid bug-bounty programme, and we would rather say so than imply one exists. The commitments above apply regardless.