Coordinated vulnerability disclosure policy

Last updated: 1-SEP-2026

Rebex welcomes responsible reports of security vulnerabilities affecting its supported products and services covered by this policy. This policy explains how to submit a report and how Rebex coordinates the handling and disclosure of reported vulnerabilities.

Scope

This policy applies to security vulnerabilities affecting software products, software components and publicly accessible online services made available or operated by Rebex under the Rebex name or trademark.

It also applies to third-party components included in or used by Rebex products or services where a vulnerability in the component may affect the security of a Rebex product or service.

Unless otherwise stated, remediation under this policy is provided for product versions within their published support period. Reports concerning older or unsupported versions are welcome, but remediation may require upgrading to a supported version.

This policy does not apply to:

Security issues affecting custom-developed software should be reported through the contact channel agreed with the relevant customer.

Reporting a vulnerability

Please report suspected vulnerabilities to:
security@rebex.net

Do not report undisclosed vulnerabilities through public forums, public issue trackers or social media.

Where possible, include:

Please do not send customer data, credentials, private keys or unnecessary personal data. Contact us first if particularly sensitive information needs to be transferred.

Reports may be submitted in English or Czech.

How Rebex handles reports

Rebex will acknowledge receipt of a vulnerability report within two business days.

We will assess whether the issue affects a covered product, investigate its impact and determine appropriate corrective or mitigating measures. We may request additional information from the reporter and may coordinate with the maintainers of affected third-party components.

The time required to resolve a vulnerability depends on its severity, complexity, affected products and third-party dependencies. Rebex does not guarantee a fixed resolution deadline.

A resolution may include a software update, configuration change, workaround, documentation change, upgrade to a supported version or coordination with a third-party component maintainer.

Coordinated disclosure

Please give Rebex a reasonable opportunity to investigate and address the vulnerability before publicly disclosing technical details.

The timing of public disclosure should be coordinated with Rebex. Normally, disclosure should take place after a corrective or mitigating measure has been made available and affected users have had a reasonable opportunity to apply it.

Rebex may disclose information earlier where this is necessary to protect users, respond to active exploitation or comply with legal reporting obligations.

Testing restrictions

This policy does not authorize testing of systems that you do not own or are not explicitly authorized to test, including systems operated by Rebex customers.

Testing must not intentionally disrupt services, damage or alter data, access more information than is necessary to demonstrate the vulnerability, use social engineering or establish persistent access.

Security advisories

Rebex publishes information about fixed vulnerabilities affecting covered products or services on its Security advisories page. Publication may be delayed where premature disclosure would create a security risk or to give affected users a reasonable opportunity to apply the relevant update or mitigation.

Rebex does not operate a public bug bounty program. Submission of a vulnerability report does not create an entitlement to financial compensation or another reward.

Other resources

See the Security center page.