Coordinated vulnerability disclosure policy
Last updated: 1-SEP-2026
Rebex welcomes responsible reports of security vulnerabilities affecting its supported products and services covered by this policy. This policy explains how to submit a report and how Rebex coordinates the handling and disclosure of reported vulnerabilities.
Scope
This policy applies to security vulnerabilities affecting software products, software components and publicly accessible online services made available or operated by Rebex under the Rebex name or trademark.
It also applies to third-party components included in or used by Rebex products or services where a vulnerability in the component may affect the security of a Rebex product or service.
Unless otherwise stated, remediation under this policy is provided for product versions within their published support period. Reports concerning older or unsupported versions are welcome, but remediation may require upgrading to a supported version.
This policy does not apply to:
- software developed specifically for an individual customer;
- vulnerabilities affecting third-party products or services that do not affect the security of a covered Rebex product or service;
- general support, licensing or configuration questions.
Security issues affecting custom-developed software should be reported through the contact channel agreed with the relevant customer.
Reporting a vulnerability
Please report suspected vulnerabilities to:
security@rebex.net
Do not report undisclosed vulnerabilities through public forums, public issue trackers or social media.
Where possible, include:
- the affected product and version;
- a description of the vulnerability and its potential impact;
- steps needed to reproduce it;
- relevant proof-of-concept code, logs or diagnostic information;
- any known exploitation or available mitigation;
- whether and when you intend to disclose the vulnerability publicly.
Please do not send customer data, credentials, private keys or unnecessary personal data. Contact us first if particularly sensitive information needs to be transferred.
Reports may be submitted in English or Czech.
How Rebex handles reports
Rebex will acknowledge receipt of a vulnerability report within two business days.
We will assess whether the issue affects a covered product, investigate its impact and determine appropriate corrective or mitigating measures. We may request additional information from the reporter and may coordinate with the maintainers of affected third-party components.
The time required to resolve a vulnerability depends on its severity, complexity, affected products and third-party dependencies. Rebex does not guarantee a fixed resolution deadline.
A resolution may include a software update, configuration change, workaround, documentation change, upgrade to a supported version or coordination with a third-party component maintainer.
Coordinated disclosure
Please give Rebex a reasonable opportunity to investigate and address the vulnerability before publicly disclosing technical details.
The timing of public disclosure should be coordinated with Rebex. Normally, disclosure should take place after a corrective or mitigating measure has been made available and affected users have had a reasonable opportunity to apply it.
Rebex may disclose information earlier where this is necessary to protect users, respond to active exploitation or comply with legal reporting obligations.
Testing restrictions
This policy does not authorize testing of systems that you do not own or are not explicitly authorized to test, including systems operated by Rebex customers.
Testing must not intentionally disrupt services, damage or alter data, access more information than is necessary to demonstrate the vulnerability, use social engineering or establish persistent access.
Security advisories
Rebex publishes information about fixed vulnerabilities affecting covered products or services on its Security advisories page. Publication may be delayed where premature disclosure would create a security risk or to give affected users a reasonable opportunity to apply the relevant update or mitigation.
Rebex does not operate a public bug bounty program. Submission of a vulnerability report does not create an entitlement to financial compensation or another reward.
Other resources
See the Security center page.