Vulnerability Disclosure Policy

Coordinated vulnerability disclosure for ForePath, Agenstra, and Decabill

Report a vulnerability

Last updated: September 9, 2026

Purpose

This Vulnerability Disclosure Policy ("Policy") applies to coordinated vulnerability disclosure between IPvX UG (haftungsbeschränkt) ("we", "us") and you regarding any published software product of ours, including ForePath (forepath.io), Agenstra (agenstra.com), Decabill (decabill.com), and software made available in the forepath/one monorepo, and defines our coordinated vulnerability disclosure ("CVD") policy under Annex I, Part II(5) of Regulation (EU) 2024/2847 (the EU Cyber Resilience Act).

Scope

We offer coordinated vulnerability disclosure for the products, services, and research activities listed below. This Policy distinguishes what you may test from what you should not. Limit testing to in-scope targets and methods. If you find an issue in something we do not operate, report it to that vendor instead. Activities listed as out of scope are not authorized under this Policy.

In scope

  • ForePath (forepath.io), Agenstra (agenstra.com), and Decabill (decabill.com)
  • Applications and libraries in the forepath/one GitHub repository
  • Publicly reachable services we operate for those products

Out of scope

  • Third-party SaaS or infrastructure we do not operate (report those issues upstream to the vendor)
  • Physical attacks, social engineering, and phishing of employees or customers
  • Denial-of-service, volumetric flooding, or resource-exhaustion testing against production
  • Already known, duplicate, or publicly disclosed issues without new impact

How to report

If you have found a security vulnerability, please use one of the private channels below. Do not file security vulnerabilities as public GitHub issues.

Email

[email protected]

Subject prefix [SECURITY]

Web form

Please use the report form further down on this page.

You can also find our contact details for automated discovery at /.well-known/security.txt (RFC 9116).

If you prefer encrypted email, please use our OpenPGP public key at /.well-known/pgp-key.txt (fingerprint 5B20 C75D E760 91CE FE8B 3CA5 2926 E9F2 4F3D 9191).

What to include

To help us assess and fix the issue quickly, please include as much of the following as you can.

  • A clear description of the vulnerability
  • The potential impact and your severity assessment
  • Detailed steps so we can reproduce the issue
  • Which products and versions are affected
  • Remediation ideas, if you have them
  • How we can reach you for follow-up

Our commitments

When you send a report, we aim to acknowledge receipt within 48 hours. After acknowledgment, we work toward the following remediation targets. These are best-effort goals, and complex issues may take longer.

Critical

Initial triage24 hours
Fix target7 days

High

Initial triage48 hours
Fix target30 days

Medium

Initial triage1 week
Fix target90 days

Low

Initial triage2 weeks
Fix targetBest effort

We generally aim for a 90-day coordinated disclosure window once a fix is available and acknowledged. We may delay public disclosure when the risk of active exploitation or incomplete patch adoption outweighs the benefit of immediate publication. That narrow delay is consistent with Annex I, Part II(4) of the CRA.

Safe harbor

If you conduct security research in good faith, follow this policy, avoid privacy violations, service disruption, and data destruction, and report your findings privately before any public disclosure, we will not pursue legal action against you for that research. This safe harbor does not authorize access beyond what is necessary to demonstrate a vulnerability. It also does not waive claims for conduct outside this policy.

Bug bounty and compensation

ForePath does not operate an official bug bounty program. There are no published reward tiers, third-party bounty platforms, or guaranteed payouts for Agenstra, Decabill, or other products in this repository. Please do not submit reports expecting a bounty.

We still welcome valid, responsibly disclosed vulnerabilities with a clear description, demonstrated impact, and reproducible steps. We may, at our sole discretion, offer recognition or compensation for especially valuable findings, but no reward is promised or owed, and any past payment does not establish a precedent.

Automated and low-effort reports are discarded without review. Mass scanner output, duplicated template submissions, and reports that are clearly AI-generated without manual verification and original analysis are rejected immediately. Please invest time in one verified finding before contacting us.

Regulatory context (EU CRA)

By providing this Policy, we meet the coordinated vulnerability disclosure obligation in Annex I, Part II(5) of Regulation (EU) 2024/2847. Actively exploited vulnerabilities and severe incidents are escalated internally so we can meet Article 14 reporting to the competent CSIRT and ENISA. That includes the early warning, notification, and final report cadence. Our operator runbook covers internal escalation. We do not publish those operational details here.

Public advisories and SBOM

Once a fix ships, we publish public advisories and release Software Bills of Materials so you can see what changed and what is included in each build.

Submit a vulnerability report

Please use this form to send a private report to our security team. We aim to acknowledge any report within 48 hours.