Skip to content

Logmanager is now part of Guardsix! Read more.

Logmanager
/ Security Center / Disclosure Policy

Coordinated Vulnerability Disclosure Policy

Version: 1.0
Effective Date: September 1st, 2026
CRA Article 14 Compliant
Maintained by: Logmanager PSIRT

Commitment to Security & Operational Integrity

At Logmanager, security is fundamental to everything we build. We value the security community and independent researchers who help keep our products, infrastructure, and customers safe. This policy outlines our guidelines for discovering, reporting, and disclosing security vulnerabilities responsibly.

01

Scope & Applicability

This policy applies to all hardware, software, cloud services, and digital assets owned or managed by Logmanager, including but not limited to:

  • Logmanager Appliance (Versions 3.x and 4.x firmware)
  • Logmanager Forwarder & Logproxy components
  • Logmanager Windows Agent
  • Logmanager Official Web Properties (*.logmanager.com, *.logmanager.io)

Out of Scope: Third-party services, applications integrated via customer APIs, physical office infrastructure, and social engineering attacks aimed at Logmanager employees.

02

Safe Harbor & Researcher Conduct

When conducting security research in good faith and in accordance with this policy, Logmanager considers your activities authorized. We will not take legal action or initiate law enforcement complaints against researchers who adhere to the following principles:

Golden Rules of Engagement

  • Do no harm: Avoid testing against production customer systems or degrading service performance.
  • Privacy protection: Never access, modify, download, or disclose customer data. If customer data is accidentally accessed, purge it immediately and notify PSIRT.
  • No destructive testing: DoS, DDoS, high-frequency brute forcing, and physical exploitation are strictly prohibited.
  • Confidentiality: Keep vulnerability details confidential until a fix is released and public disclosure is coordinated.
03

Reporting Process & Response SLA

If you suspect you have identified a vulnerability, please submit your findings through our secure portal or email our Product Security Incident Response Team (PSIRT).

Primary Submission Portal: https://logmanager.com/security/vulnerability-report/
PGP / Encrypted Email: [email protected]
PGP Key ID: 0xA1B2C3D4 (Fingerprint: 8F2A 9C10 E451 …)

Upon receiving a vulnerability report, the Logmanager PSIRT team commits to the following timelines:

  1. Acknowledgement: Within 24 business hours of report submission.
  2. Initial Assessment & Triage: Within 3 business days, confirming severity (CVSS v3.1/v4.0) and applicability.
  3. Status Updates: Regular updates provided at least every 10 business days until remediation.
04

Cyber Resilience Act (CRA) & Regulatory Reporting

Regulatory Notice (EU Cyber Resilience Act):
If a reported vulnerability is determined to be actively exploited in the wild, Logmanager is legally mandated under EU CRA Article 14 to notify the European Union Agency for Cybersecurity (ENISA) and competent national CSIRTs within 24 hours of becoming aware.

Please clearly highlight in your initial report if you have evidence or reasonable suspicion of active exploitation in customer or production environments.

05

Remediation & Disclosure Timeline

Logmanager operates under a standard 90-day coordinated disclosure timeline:

  • Standard Vulnerabilities: Fixes are issued within 90 days. Public security advisories and CVE publication take place upon patch release.
  • Critical / Actively Exploited Issues: Accelerated remediation workflows are triggered immediately. Emergency patches or mitigations are targeted within 7 to 14 days.

We believe in full credit for researchers. If desired, your name or alias will be recognized in our Security Advisory Release Notes and Hall of Fame.

Ready to submit a security finding?

Use our secure encrypted vulnerability submission form to submit step-by-step reproduction details.

Go to Vulnerability Report Form →