Draft. This page is a draft awaiting approval. It may change before it is final, and it should not be relied on until this notice is removed.
If you believe you have found a security vulnerability in Keystone or in this website, please tell us. Reports are welcome.
How to report
Write to [email protected]. Please report privately, to that address, and not in a public place.
What to include
- what you found, and where: the address of the page, or the part of the product
- the steps that reproduce it
- what you think someone could do with it
- anything that helps us see it, such as a proof of concept, a request and response, or a screenshot
- how to reach you, if you would like a reply
Please do not include personal information about anyone else.
What we ask of you
- do not view, change or delete information that is not yours
- stop once you have enough to show the problem, and tell us then
- do not disrupt or slow the site for other people, for example by flooding it with requests
- do not use social engineering or physical attacks
- give us a reasonable chance to fix a problem before you make it public
What we will do
We will look into what you send us and write back to you if you have told us how.
This page makes no promise about how quickly we will reply or fix a problem, sets no timetable for disclosure, and offers no reward. It does not change what the law allows.
What a report is likely to be about
KeystoneIT has not been released, and no installation of it is open to the public. In practice a report today will be about this website.
Where we stand
No external penetration test has been carried out, and we hold no security certifications today. The security page sets out what is in place and what is not.
This contact is also published in machine-readable form at /.well-known/security.txt.
This page is published by Alresford Systems Ltd, registered in England and Wales, company number 16940599, registered office 33 Alresford Road, Salford, England, M6 7QJ.