Security reports go to info@41bit.io. Tell us what you found, where, and how to reproduce it. We reply, and we do not pursue researchers who report in good faith.
How to report
Describe the issue, where it appears, and how we can reproduce it. Version, system, and proof-of-concept details are optional.
Please allow time for investigation and a fix before publication. We will keep you updated.
What happens next
We acknowledge every report and explain how we will assess it. If we do not consider something a security issue, we tell you why. If it is valid, we keep you updated while we work on the fix.
We do not offer a paid bounty yet. With permission, we credit the reporter in the release note that contains the fix.
We do not pursue researchers who report in good faith. Testing your own installation or systems without accessing another person’s account, device, or data is not treated as hostile activity.
What this covers
This policy covers our website, company contact and release-note services, download and update services we operate, and software we distribute.
If the issue is in a third-party provider, report it to that provider as well. Tell us if it affects our customers, software, or data.
If the finding belongs to an operating system or another platform rather than our software, report it to the platform provider. We still want to know if it changes the risk for our users.
Where we publish from
41BIT publishes company information and sends company email from 41bit.io.
Software, websites, or email claiming to represent 41BIT from another domain are not ours. If you find something impersonating us, send the details to info@41bit.io and we will investigate.