Decent Espresso strives to provide safe and secure products and services. We prefer a responsible coordinated disclosure of security vulnerabilities.
We appreciate your effort to reduce harm to our customers and systems. We commit to decent and timely communication. We also commit to no punitive action against you when using our responsible coordinated disclosure approach.
We prefer you report the vulnerability privately to us before public disclosure. Please report it to us by sending an email to decentespresso@gmail.com.
We request you include, when possible, the following information to help us understand the issue:
- Brief description of the vulnerability
- Impact (e.g. data loss, unauthorized access, equipment failure, physical harm, etc.)
- Affected models or versions, configuration, setup
- Detailed steps to reproduce the vulnerability
- Evidence of the vulnerability (e.g. screenshots, logs, etc.)
- Expected secure behavior
- Proof of concept or exploit code (if applicable) in a ZIP file, private git repository, etc.
- Your contact information (email, phone number, etc.)
We prefer security vunerability communication in English.
- We will send you an automated response within 24 hours acknowledging receipt of your email report. If this fails, please resend your email or use another method.
- We will personally contact you to verify the vulnerability within 5 business days. We ask for your patience since we may need additional information or clarification.
- We will keep you informed of our triage progress with decent timelines.
- After triage, we will provide you with a summary of the vulnerability and our response.
- When triage approves remediation, we will do so in a timely manner while keeping you informed.
- We will work with you to coordinate the public disclosure of the vulnerability after remediation is available.
- We will acknowledge your contributions in our public disclosure. We will respect your privacy and anonymity if you request it.
flowchart TB
report([Report to Decent Espresso])
autoreply([Automated Response 24 hrs])
personalcontact([Personal Contact 5 biz days])
verify([Verify Vulnerability])
triage([Triage])
summary([Summarize and Respond])
remediate([Remediate])
coordinate([Coordinate Disclosure])
disclose([Public Disclosure])
report --> autoreply
autoreply --> personalcontact
personalcontact --> verify
verify -->|clarify| personalcontact
verify --> triage
triage --> summary
summary --> remediate
summary --> disclose
remediate --> coordinate
coordinate --> disclose
We do not at this time offer a bug bounty program. We appreciate your responsible disclosure of security vulnerabilities.