Security

Report a vulnerability. Here is what happens next.

We sell tooling for coordinated vulnerability disclosure, so ours is public and specific. This page tells you where to send a finding, what we commit to in return, and what we will not do to you for telling us.

Where to send it

Email security@musterproof.com. The machine-readable version of this page is at /.well-known/security.txt.

Useful reports name the affected component and version, describe the impact, and include enough detail to reproduce. A screenshot of a scanner result without a reproduction is not a report, and we will ask you for one before we can act.

What we commit to

AcknowledgementWithin 3 working days.
Initial assessmentWithin 10 working days, with a severity and a plan.
Progress updatesAt least every 14 days while the report is open.
CreditNamed in the fix note, unless you would rather not be.
Public disclosureCoordinated with you, and by default 90 days from the report or on release of the fix, whichever comes first.

Safe harbour

Research carried out in good faith under this policy will not be met with legal action from us, and we will not ask a third party to take action either. Good faith means you stayed within our own systems, used only accounts you control, took no more data than needed to demonstrate the finding, deleted what you took, and gave us a reasonable chance to fix the issue before telling anybody else.

Out of scope: denial of service, physical attacks, social engineering of our staff or our suppliers, and anything that degrades the service for a customer. We do not run a paid bounty. Promising money we have not budgeted would convert a helpful stranger into an aggrieved one, in public.

What we do with your data

Where it livesDatabase in the Cloudflare Western Europe region; object storage in the Cloudflare EU jurisdiction, which is a residency guarantee rather than a placement hint.
SBOM contentsEncrypted before they reach storage, with a separate key per object wrapped by a master key we can rotate without touching your data.
Personal dataThe minimum a compliance package needs: the email address you sign in with, and the names you give your own products. An SBOM does not contain personal data by design, and we keep it that way.
Third partiesVulnerability data is pulled from OSV, the CISA catalogue of known exploited vulnerabilities and FIRST EPSS on a schedule. Your data is never sent to them; we query by package coordinates only.
DeletionMarked on request and physically removed within 30 days, including the object storage prefix that holds your uploads.

A dependency map of your product is an attack plan against you. We treat it as one: nobody browses a bucket, and the master key lives outside the account that holds the data.

Our own compliance position

Musterproof is standalone software as a service and is therefore outside the scope of the Cyber Resilience Act itself. We say that plainly rather than implying otherwise, because a vendor who overstates their own obligations is not a good guide to yours. What we do run is the same disclosure process we help you build, which is a better argument than a badge.