Vulnerability Disclosure Policy

Last updated

Effective date

Duplicati Inc takes the security of our software and services seriously, and we value the work of security researchers who help us find and fix problems. This policy explains how to report a vulnerability to us, what you can expect from us, and what we ask of you.

Scope

This policy covers:

  • The Duplicati Console at *.duplicati.com and its APIs

  • The Duplicati machine-server relay and remote-management tunnel

  • Duplicati-provided backup storage

  • The Duplicati client software (Duplicati and Duplicati Enterprise), including its reduced-reporting and encryption features

  • Duplicati's public websites

Issues in third-party services we use (hosting providers, payment processors, support tools) should be reported to those providers under their own policies. If you are unsure whether something is in scope, report it anyway and we will tell you.

How to report

Email security@duplicati.com. Please include:

  • A description of the issue and its potential impact

  • Steps to reproduce, or a proof of concept

  • The product, version, URL, or component affected

  • How you would like to be credited, if at all

If your report contains sensitive details, ask us for a PGP key or a secure channel before sending them. Do not send customer data or other people's personal information in a report; describe it instead.

What we commit to

  • Acknowledge your report within 3 working days.

  • Assess it and tell you our initial view of severity and the component responsible within 10 working days.

  • Keep you informed of progress toward a fix at reasonable intervals, and tell you when the fix is released.

  • Fix confirmed issues on a schedule matched to their severity: critical issues as fast as we safely can, typically within days; high within 30 days; others in a scheduled release.

  • Credit you in our release notes if you wish, once the fix is public.

  • Not take legal action against you for research conducted in good faith under this policy.

We do not currently run a paid bug bounty programme. We may offer a token of thanks for significant findings at our discretion.

What we ask of you

  • Give us a reasonable time to fix the issue before disclosing it publicly. We ask for 90 days from acknowledgement, or longer by agreement if a fix is complex; we will not ask you to wait indefinitely.

  • Make a good-faith effort to avoid harm: do not access, modify, or delete data that is not yours; do not degrade or disrupt the service; stop and report as soon as you have enough to demonstrate the issue.

  • Only test against accounts and organizations you own or have explicit permission to use. Never test against another customer's organization.

  • If you encounter customer data, personal information, or anything that looks like health information during testing, stop, do not retain it, and tell us in your report.

  • Do not use social engineering, phishing, or physical attacks against Duplicati staff, customers, or providers.

  • Comply with applicable law.

Safe harbour

Research that follows this policy is authorised. We will not pursue civil or criminal action, or refer you to law enforcement, for good-faith security research that stays within the rules above. If a third party takes legal action against you for activity conducted in accordance with this policy, we will make it known that your actions were authorised. This safe harbour does not extend to actions outside this policy or to anyone who uses this policy as cover for malicious activity.

Out of scope

The following are not vulnerabilities for the purposes of this policy and will not be prioritised:

  • Reports from automated scanners without a demonstrated impact

  • Missing security headers, best-practice recommendations, or configuration opinions without an exploit

  • Denial-of-service findings, rate-limiting, or brute-force issues that require high volume

  • Issues in outdated client versions that are fixed in the current release

  • Clickjacking on pages with no sensitive actions

  • Email configuration findings (SPF, DKIM, DMARC) on domains that do not send mail

  • Vulnerabilities in third-party services or in software not developed by Duplicati

  • Social engineering of Duplicati staff or customers

Recognition

Researchers who report valid issues and want to be credited can be listed in the release notes for the fix.

Contact

security@duplicati.com · Duplicati Inc, a Delaware corporation