Reporting a Security Vulnerability
If you have found a security problem in our firmware, in DSPconfig or on this website, we would like to hear about it. This page is how to tell us, and what we will do about it.
How to report
Email [email protected] with enough detail for us to reproduce the problem: the product and firmware version, what you did, and what happened.
Please give us a reasonable opportunity to fix the problem before describing it publicly. We will not take legal action against anyone who reports a vulnerability in good faith, keeps to the terms on this page, and does not access, alter or destroy anyone else's data while investigating.
What happens next
- We will acknowledge your report within 5 working days.
- We will tell you whether we consider it a vulnerability, and why, within 30 days.
- If it is one, we will agree a disclosure timetable with you and credit you when we publish the fix, unless you would rather we did not.
What is in scope
Firmware running on our hardware, the DSPconfig application, and this website. Reports about the security of third-party services we use are better sent to those services directly.