CrabNebula Cloud is now free. Learn why

Vulnerability Disclosure Policy

Our commitments

At crabnebula.dev, our vulnerability disclosure policy is designed to keep our products secure after release.

After receiving your report, we will:

  • Confirm its reception within 5 working days
  • Update you with our progress every 2 weeks
  • Aim to resolve the reported issues within 90 days

Should we need more time to resolve your findings, we may ask you to avoid disclosing them until a solution is in place.

If you wish, we can acknowledge you after the issue is resolved.

Please visit https://crabnebula.dev/.well-known/security.txt for communication preferences, and reference https://crabnebula.dev/.well-known/pgp.txt for PGP keys.

CrabNebula Ltd. will not pursue legal action when reporting vulnerabilities in accordance with the policy.

Your commitments

Please respect all applicable regulations and always remain responsible!

You are a good person and we appreciate you.

Report a vulnerability

You can report security issues discovered in our products, in our software (proprietary or open-source) or in any associated services.

To report a vulnerability, please email security@crabnebula.dev with the following information:

  • The product(s) or asset(s) where you discovered the vulnerabilities
  • Details on the vulnerabilities and how to exploit them
  • If you want to be acknowledged

If your report contains sensitive details, please encrypt it with our PGP key.