Responsible Disclosure Policy

Every vulnerability we find in third-party software is reported to the vendor and patched before we publish. The goal is a fix, not a headline. All of our research follows this policy.

The process

  1. Notify the vendor. As soon as we have a clear picture of the issue, we report it, and we try more than one channel to reach the right people.
  2. Protect affected clients. If a client of ours is exposed, we give them mitigations that do not reveal the underlying issue.
  3. Give the vendor 90 days. Ninety days is the industry-standard window. We extend it when a complex issue genuinely needs more time.
  4. Coordinate the release. We publish in coordination with the vendor, so nothing goes public before a patch is available.

Found something in one of our own systems? Email contact@baldur.dk and we will respond.