Policy
Disclosure policy
This policy is being written and is not settled. Rather than publish something we have not agreed, this page says only what is true today.
Reporting something to us
Email hello@northbeams.com with "Labs disclosure" in the subject. It reaches Northbeams, and it is the route until this policy is published.
Useful in a report: what you found, where you found it, and how to see it again. That applies both to a security issue in a Labs tool and to a factual error in something published here.
Do not put anything sensitive in a first email. Ask for another route and one will be arranged.
What is not decided yet
Named here so the gap is visible rather than implied:
- What we do when Labs research finds a problem in software published by someone else, including who we tell, in what order, and how long we wait before writing about it.
- Whether a fixed timeline is published, and what happens when a vendor does not reply.
- How credit is given to a reporter, and whether reports can stay anonymous.
These are open decisions. This page gets replaced when they are made.
What already applies
These rules are settled, and they cover most of what a disclosure policy is for:
- Third parties are described neutrally and factually, never as villains.
- Every figure published here says where it came from and how it was counted.
- What a method could not see is published alongside the findings.
- Nothing goes out that would not survive the people it names checking it line by line.