Logmanager is now part of Guardsix! Read more.
Take a Product Tour
Explore the user interface, features, and capabilities of Logmanager
Quick Start Guide
Deploy Logmanager in your virtual environment
Join our Team
Explore open job opportunities and become part of a team building meaningful technology.
Logmanager welcomes reports of security vulnerabilities in our products. We are committed to working with security researchers, customers, and the wider community to verify, remediate, and disclose vulnerabilities in a coordinated way that protects our users. If you report a vulnerability in good faith under this policy, we will work with you openly and will not pursue legal action against you (see §8, Safe Harbour).
The preferred way to report a vulnerability is our vulnerability report form. The form is transmitted over TLS and is delivered directly into a restricted-access system monitored by our PSIRT. It captures the details we need and lets us track your report securely from the moment it arrives — so please use it whenever possible.
Alternatively, existing customers may report a vulnerability through our customer support channel, which routes security reports to the PSIRT. Please do not send vulnerability details by unencrypted email.
You may submit anonymously via the form. If you do, we will still process your report, but we will be unable to send you updates or credit you in the advisory.
To help us verify and address the issue quickly, please include:
Please do not test against production systems, customer environments, or live services. Do not access, modify, or exfiltrate data that is not yours.
In scope — vulnerabilities in Logmanager products with digital elements that are currently supported by us, including:
Out of scope:
We ask that you keep the details of the vulnerability confidential until we have jointly agreed a disclosure date, so that our users are not put at risk before a fix is available.
If you have any evidence of active exploitation, please tell us clearly and immediately in your report, as it directly affects these obligations. This regulatory reporting is handled by Logmanager and does not require any action from you.
With your consent, we will credit you by name or alias in the security advisory for vulnerabilities you report to us and that we confirm. If you prefer to remain anonymous, we will respect that.
If you make a good-faith effort to comply with this policy during your research, Logmanager will consider your research to be authorised, will work with you to understand and resolve the issue quickly, and will not recommend or pursue legal action against you in connection with your report. This includes research that unintentionally goes slightly beyond scope, provided you act in good faith, stop when you realise, and do not compromise the privacy or safety of our users or the availability of our services.
This safe harbour does not apply to actions that are unlawful, that intentionally harm users or systems, that access or exfiltrate data beyond what is necessary to demonstrate the vulnerability, or that violate the privacy of others. In particular, the following activities are explicitly not covered and are not authorised:
Once a fix or effective mitigation is available, we publish a signed security advisory on our security advisory channel, including the affected products/versions, impact, severity, remediation steps, and — with consent — credit to the reporter. Where a CVE identifier applies, we request and reference one.
We may update this policy from time to time. The version and “last updated” date at the top of this page indicate the current revision.
Use our secure vulnerability report form to submit step-by-step reproduction details.