Vulnerability Disclosure Policy
Ubuntu Software is committed to the security of our products and services. We welcome reports from security researchers who discover potential vulnerabilities.
Safe Harbor
We consider security research conducted in accordance with this policy to be:
- Authorized — We will not pursue legal action against you
- Helpful — We value your contribution to improving our security
- Protected — We will work with you to understand and resolve the issue
If you make a good-faith effort to comply with this policy during your research, we will not initiate or recommend legal action against you.
Scope
This policy applies to all Ubuntu Software products and services:
| In Scope | Examples |
|---|---|
| Website | www.ubuntusoftware.net |
| Publish Platform | Publishing and design tools |
| Spatial Platform | Robotics and simulation |
| APIs | Public API endpoints |
| Open Source | Our public repositories |
Prohibited Activities
To protect our users and systems, please refrain from:
- Denial-of-service attacks
- Social engineering of employees or contractors
- Physical access attempts
- Accessing or modifying data belonging to other users
- Automated vulnerability scanning that degrades service
- Public disclosure before we’ve had time to respond
How to Report
Use our Contact Form to submit your report.
Please include:
- Description — What is the vulnerability?
- Location — Where did you find it? (URL, component, version)
- Impact — What could an attacker do with this?
- Steps — How can we reproduce it?
- Proof of Concept — Screenshots, code, or logs (if available)
You may report anonymously. We don’t require personal information.
Our Commitment
| Action | Timeline |
|---|---|
| Acknowledge receipt | Within 3 business days |
| Initial assessment | Within 10 business days |
| Status updates | Every 30 days until resolved |
| Target resolution | 90 days (industry standard) |
We’ll keep you informed of our progress and notify you when the issue is fixed.
Recognition
We believe in thanking researchers who help us improve security. Valid reports are recognized on our Security Acknowledgments page.
We currently don’t offer monetary rewards, but we’re grateful for your contribution to making our products more secure.
Questions?
For questions about this policy or clarification on scope:
Machine-Readable Policy
Security researchers can find our security.txt file at the standard location per RFC 9116.