Community

Reporting a security issue

Nixt DNA Server receives mail from the whole internet and holds private correspondence; the apps open files and mail from strangers. We treat every security report as a priority, and we say what we will do with it and when.

How to report

Write to security@nixtoffice.com. Do not report a security problem anywhere public, including the community channels or a review.

Please include:

  • the product and its version;
  • for Nixt DNA Server, how it is deployed (one machine, a cluster, a container, Kubernetes);
  • the protocol, screen or component involved;
  • the steps to reproduce it, and what you believe the impact is.

A proof of concept helps. Reaching into other people’s mailboxes or data does not, and is outside the safe harbour below.

What we do, and when

StepWhen
We acknowledge your report.Within one business day.
We assess how it can be exploited, which versions it affects, and whether it is already being exploited.Within three business days.
We release a fix for every supported release channel.Our target is 30 days, and 72 hours for a critical issue.
We publish an advisory with the affected versions, what to do, and credit to you.With the fix.

Disclosure

We ask for ninety days from our acknowledgement before you disclose the issue publicly, or less by agreement once a fix is available. If we learn an issue is being exploited, we publish at once with whatever mitigation exists. We credit you in the advisory unless you would rather not be named.

Safe harbour

Good-faith research on your own installation, or on a test organisation we have given you, that follows this page will not lead to legal action from Nixt Atlantic. Accessing, changing or copying other people’s data, degrading a shared service, or trying to deceive our staff is not good faith.

Which versions are fixed

A fix ships in a new release. Install the newest release to receive it.