Vulnerability Disclosure Policy
Last updated
Effective date
Duplicati Inc takes the security of our software and services seriously, and we value the work of security researchers who help us find and fix problems. This policy explains how to report a vulnerability to us, what you can expect from us, and what we ask of you.
Scope
This policy covers:
The Duplicati Console at *.duplicati.com and its APIs
The Duplicati machine-server relay and remote-management tunnel
Duplicati-provided backup storage
The Duplicati client software (Duplicati and Duplicati Enterprise), including its reduced-reporting and encryption features
Duplicati's public websites
Issues in third-party services we use (hosting providers, payment processors, support tools) should be reported to those providers under their own policies. If you are unsure whether something is in scope, report it anyway and we will tell you.
How to report
Email security@duplicati.com. Please include:
A description of the issue and its potential impact
Steps to reproduce, or a proof of concept
The product, version, URL, or component affected
How you would like to be credited, if at all
If your report contains sensitive details, ask us for a PGP key or a secure channel before sending them. Do not send customer data or other people's personal information in a report; describe it instead.
What we commit to
Acknowledge your report within 3 working days.
Assess it and tell you our initial view of severity and the component responsible within 10 working days.
Keep you informed of progress toward a fix at reasonable intervals, and tell you when the fix is released.
Fix confirmed issues on a schedule matched to their severity: critical issues as fast as we safely can, typically within days; high within 30 days; others in a scheduled release.
Credit you in our release notes if you wish, once the fix is public.
Not take legal action against you for research conducted in good faith under this policy.
We do not currently run a paid bug bounty programme. We may offer a token of thanks for significant findings at our discretion.
What we ask of you
Give us a reasonable time to fix the issue before disclosing it publicly. We ask for 90 days from acknowledgement, or longer by agreement if a fix is complex; we will not ask you to wait indefinitely.
Make a good-faith effort to avoid harm: do not access, modify, or delete data that is not yours; do not degrade or disrupt the service; stop and report as soon as you have enough to demonstrate the issue.
Only test against accounts and organizations you own or have explicit permission to use. Never test against another customer's organization.
If you encounter customer data, personal information, or anything that looks like health information during testing, stop, do not retain it, and tell us in your report.
Do not use social engineering, phishing, or physical attacks against Duplicati staff, customers, or providers.
Comply with applicable law.
Safe harbour
Research that follows this policy is authorised. We will not pursue civil or criminal action, or refer you to law enforcement, for good-faith security research that stays within the rules above. If a third party takes legal action against you for activity conducted in accordance with this policy, we will make it known that your actions were authorised. This safe harbour does not extend to actions outside this policy or to anyone who uses this policy as cover for malicious activity.
Out of scope
The following are not vulnerabilities for the purposes of this policy and will not be prioritised:
Reports from automated scanners without a demonstrated impact
Missing security headers, best-practice recommendations, or configuration opinions without an exploit
Denial-of-service findings, rate-limiting, or brute-force issues that require high volume
Issues in outdated client versions that are fixed in the current release
Clickjacking on pages with no sensitive actions
Email configuration findings (SPF, DKIM, DMARC) on domains that do not send mail
Vulnerabilities in third-party services or in software not developed by Duplicati
Social engineering of Duplicati staff or customers
Recognition
Researchers who report valid issues and want to be credited can be listed in the release notes for the fix.
Contact
security@duplicati.com · Duplicati Inc, a Delaware corporation
