Skip to content

Logmanager is now part of Guardsix! Read more.

Logmanager
/ Security Center / Disclosure Policy

Coordinated Vulnerability Disclosure Policy

Version: 1.0
Last updated: 2026-11-09
CRA Article 14
Maintained by: Logmanager PSIRT

Our Commitment

Logmanager welcomes reports of security vulnerabilities in our products. We are committed to working with security researchers, customers, and the wider community to verify, remediate, and disclose vulnerabilities in a coordinated way that protects our users. If you report a vulnerability in good faith under this policy, we will work with you openly and will not pursue legal action against you (see §8, Safe Harbour).

01

How to Report — Preferred Contact Mechanism

The preferred way to report a vulnerability is our vulnerability report form. The form is transmitted over TLS and is delivered directly into a restricted-access system monitored by our PSIRT. It captures the details we need and lets us track your report securely from the moment it arrives — so please use it whenever possible.

Alternatively, existing customers may report a vulnerability through our customer support channel, which routes security reports to the PSIRT. Please do not send vulnerability details by unencrypted email.

You may submit anonymously via the form. If you do, we will still process your report, but we will be unable to send you updates or credit you in the advisory.

02

What to Include in Your Report

To help us verify and address the issue quickly, please include:

  • The affected product and version (e.g. Logmanager Appliance 4.1.2) and component/module if known.
  • The vulnerability type and a clear description of the issue, including root cause and affected code path where possible.
  • Step-by-step reproduction instructions and, ideally, a proof of concept.
  • The impact you believe the vulnerability has, and a CVSS vector if you have one.
  • Whether you have any evidence the vulnerability is being actively exploited (this is important — see §6).
  • How you would like to be credited (or that you wish to remain anonymous).

Please do not test against production systems, customer environments, or live services. Do not access, modify, or exfiltrate data that is not yours.

03

Scope

In scope — vulnerabilities in Logmanager products with digital elements that are currently supported by us, including:

  • Logmanager Appliance — software and firmware/OS
  • Logmanager Forwarder
  • Logmanager Windows Agent
  • Logmanager Logproxy
  • Bundled third-party / open-source components shipped as part of these products
  • The Logmanager website (logmanager.com), where a security issue affects users

Out of scope:

  • Social engineering, phishing, or physical attacks against Logmanager staff or facilities
  • Denial-of-service testing, or volumetric/load testing against any live system
  • Reports from automated scanners without a demonstrated, exploitable impact
  • Missing security hardening headers or best-practice recommendations with no direct impact
  • Products or versions that are no longer supported at the time of the report
  • Findings that require a compromised device, rooted/jailbroken environment, or physical access, absent a realistic attack scenario
04

What You Can Expect From Us — Communication & Timeline

  1. Acknowledgement: we will acknowledge your report within 2 business days and begin triage.
  2. Validation: we will verify the report, assess severity (CVSS v4.0), and let you know whether we have confirmed it as a vulnerability.
  3. Updates: we will keep you informed of remediation progress and the expected fix timeline.
  4. Coordinated disclosure: our default coordination window is 90 days from acknowledgement. We aim to release a fix and a public security advisory within that window and will coordinate the public disclosure date with you.
  5. Extensions: for complex issues we may need more time; we will discuss this with you rather than let a deadline pass silently.

We ask that you keep the details of the vulnerability confidential until we have jointly agreed a disclosure date, so that our users are not put at risk before a fix is available.

If you plan to disclose without coordination: we understand you are entitled to publish your own findings. If you intend to disclose before a fix is available, please tell us as early as possible. We will do our best to expedite a fix or an interim mitigation and to publish an advisory to protect our users, and we will work with you on the shortest realistic timeline. Publishing exploit details before users can protect themselves puts them at direct risk, so we strongly encourage coordination — but choosing to disclose does not, by itself, remove the good-faith protections in §8.
05

Actively Exploited Vulnerabilities & Regulatory Reporting

Regulatory Notice (EU Cyber Resilience Act):
If a vulnerability in a Logmanager product is being actively exploited, we are legally required under the EU Cyber Resilience Act (Regulation (EU) 2024/2847, Article 14) to notify the relevant authorities — the Czech national CSIRT (NÚKIB) and ENISA — within short, mandated deadlines (an early warning within 24 hours).

If you have any evidence of active exploitation, please tell us clearly and immediately in your report, as it directly affects these obligations. This regulatory reporting is handled by Logmanager and does not require any action from you.

06

Recognition

With your consent, we will credit you by name or alias in the security advisory for vulnerabilities you report to us and that we confirm. If you prefer to remain anonymous, we will respect that.

07

Safe Harbour

Good-Faith Research Is Protected

If you make a good-faith effort to comply with this policy during your research, Logmanager will consider your research to be authorised, will work with you to understand and resolve the issue quickly, and will not recommend or pursue legal action against you in connection with your report. This includes research that unintentionally goes slightly beyond scope, provided you act in good faith, stop when you realise, and do not compromise the privacy or safety of our users or the availability of our services.

This safe harbour does not apply to actions that are unlawful, that intentionally harm users or systems, that access or exfiltrate data beyond what is necessary to demonstrate the vulnerability, or that violate the privacy of others. In particular, the following activities are explicitly not covered and are not authorised:

  • Social engineering, phishing, or physical attacks against Logmanager staff or facilities.
  • Denial-of-service testing, or volumetric/load testing against any live system.
  • Unauthorised access to, or accessing, modifying, or exfiltrating, customer data — including any data belonging to Logmanager customers or their end users.
08

Publication

Once a fix or effective mitigation is available, we publish a signed security advisory on our security advisory channel, including the affected products/versions, impact, severity, remediation steps, and — with consent — credit to the reporter. Where a CVE identifier applies, we request and reference one.

09

Changes to This Policy

We may update this policy from time to time. The version and “last updated” date at the top of this page indicate the current revision.

Ready to submit a security finding?

Use our secure vulnerability report form to submit step-by-step reproduction details.

Go to Vulnerability Report Form →