Coordinated vulnerability disclosure for ForePath, Agenstra, and Decabill
Last updated: September 9, 2026
This Vulnerability Disclosure Policy ("Policy") applies to coordinated vulnerability disclosure between IPvX UG (haftungsbeschränkt) ("we", "us") and you regarding any published software product of ours, including ForePath (forepath.io), Agenstra (agenstra.com), Decabill (decabill.com), and software made available in the forepath/one monorepo, and defines our coordinated vulnerability disclosure ("CVD") policy under Annex I, Part II(5) of Regulation (EU) 2024/2847 (the EU Cyber Resilience Act).
We offer coordinated vulnerability disclosure for the products, services, and research activities listed below. This Policy distinguishes what you may test from what you should not. Limit testing to in-scope targets and methods. If you find an issue in something we do not operate, report it to that vendor instead. Activities listed as out of scope are not authorized under this Policy.
If you have found a security vulnerability, please use one of the private channels below. Do not file security vulnerabilities as public GitHub issues.
Web form
Please use the report form further down on this page.
You can also find our contact details for automated discovery at /.well-known/security.txt (RFC 9116).
If you prefer encrypted email, please use our OpenPGP public key at /.well-known/pgp-key.txt (fingerprint 5B20 C75D E760 91CE FE8B 3CA5 2926 E9F2 4F3D 9191).
To help us assess and fix the issue quickly, please include as much of the following as you can.
When you send a report, we aim to acknowledge receipt within 48 hours. After acknowledgment, we work toward the following remediation targets. These are best-effort goals, and complex issues may take longer.
Critical
High
Medium
Low
We generally aim for a 90-day coordinated disclosure window once a fix is available and acknowledged. We may delay public disclosure when the risk of active exploitation or incomplete patch adoption outweighs the benefit of immediate publication. That narrow delay is consistent with Annex I, Part II(4) of the CRA.
If you conduct security research in good faith, follow this policy, avoid privacy violations, service disruption, and data destruction, and report your findings privately before any public disclosure, we will not pursue legal action against you for that research. This safe harbor does not authorize access beyond what is necessary to demonstrate a vulnerability. It also does not waive claims for conduct outside this policy.
ForePath does not operate an official bug bounty program. There are no published reward tiers, third-party bounty platforms, or guaranteed payouts for Agenstra, Decabill, or other products in this repository. Please do not submit reports expecting a bounty.
We still welcome valid, responsibly disclosed vulnerabilities with a clear description, demonstrated impact, and reproducible steps. We may, at our sole discretion, offer recognition or compensation for especially valuable findings, but no reward is promised or owed, and any past payment does not establish a precedent.
Automated and low-effort reports are discarded without review. Mass scanner output, duplicated template submissions, and reports that are clearly AI-generated without manual verification and original analysis are rejected immediately. Please invest time in one verified finding before contacting us.
By providing this Policy, we meet the coordinated vulnerability disclosure obligation in Annex I, Part II(5) of Regulation (EU) 2024/2847. Actively exploited vulnerabilities and severe incidents are escalated internally so we can meet Article 14 reporting to the competent CSIRT and ENISA. That includes the early warning, notification, and final report cadence. Our operator runbook covers internal escalation. We do not publish those operational details here.
Once a fix ships, we publish public advisories and release Software Bills of Materials so you can see what changed and what is included in each build.
Please use this form to send a private report to our security team. We aim to acknowledge any report within 48 hours.