diff --git a/SECURITY.md b/SECURITY.md index 5ac7581b3a7..4dc93d09c4f 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -6,11 +6,31 @@ | ------- | ------------------ | | 11.x.x | :white_check_mark: | | 10.0.x | :white_check_mark: | -| 8.0.x | :white_check_mark: | +| 8.0.x | :white_check_mark: | | <= 7.x.x | :x: | ## Reporting a Vulnerability -Please report (suspected) security vulnerabilities at [https://support.axonivy.com/](https://support.axonivy.com/) . -You will receive a response from us within 72 hours. -If the issue is confirmed, we will release a patch as soon as possible depending on complexity but historically within a few days. +At Axon Ivy, we take security seriously. If you believe you've found a security vulnerability in our software, we encourage you to let us know right away. We investigate all reported vulnerabilities promptly. + +To report a vulnerability, please send an email to [security@axonivy.com](mailto:security@axonivy.com) with the following information: + +- Description of the vulnerability +- Steps to reproduce the vulnerability +- Any additional information or context that may be helpful + +Please refrain from publicly disclosing the vulnerability until it has been addressed by our team. + +## Response Time + +We strive to respond to security vulnerability reports as quickly as possible. Upon receiving your report, we will acknowledge it within 72 hours and we will release a patch as soon as possible depending on complexity, but historically within a few days. +Please report (suspected) security vulnerabilities at https://support.axonivy.com/ . + + +## Responsible Disclosure + +We encourage responsible disclosure of security vulnerabilities. We believe that working together with security researchers and the broader community helps us improve the security of our software for everyone. + +## Contact + +For any questions or concerns regarding security, please contact us at [security@axonivy.com](mailto:security@axonivy.com).