Skip to content
Northbeams Labs

Policy

Disclosure policy

This policy is being written and is not settled. Rather than publish something we have not agreed on, this page says only what is true today.

Reporting something to us

Email hello@northbeams.com with "Labs disclosure" in the subject. It reaches Northbeams, and it is the route until this policy is published.

What is useful in a report: what you found, where you found it, and how we can see it again ourselves. That holds for a security issue in a Labs tool and equally for a factual error in something published here.

Do not put anything sensitive in a first email. Ask for another route and one will be arranged.

What is not decided yet

Named here so the gap is visible rather than implied:

  • What we do when Labs research finds a problem in software published by someone else. That covers who we tell, in what order, and how long we wait before writing about it.
  • Whether a fixed timeline is published, and what happens when a vendor does not reply.
  • How credit is given to a reporter. Also whether a report can stay anonymous.

These are open decisions. This page gets replaced when they are made.

What already applies

These rules are settled, and they cover most of what a disclosure policy is for:

  • Third parties are described neutrally and factually. Never as villains.
  • Every figure published here says where it came from and how it was counted.
  • What a method could not see is published alongside the findings.
  • Nothing goes out that would not survive the people it names checking it line by line.