Skip to content

Security: cloudops/ReLVHDoISCSISR

Security

SECURITY.md

Security Policy

Aptum takes the security of our software and services seriously. Thank you for helping us keep them safe.

Reporting a vulnerability

Email security@aptum.com.

Do not open a public issue, pull request, or discussion for a security problem. A public report tells attackers about the flaw before we can fix it.

Include as much of the following as you can:

  • The repository, product, service, or URL affected.
  • A description of the vulnerability and what an attacker could do with it.
  • Steps to reproduce it, or a proof of concept.
  • Any configuration, version, or environment details that matter.

Write in English. We accept reports in any format, but the more detail you give us, the faster we can confirm and fix the problem.

Scope

This policy covers:

  • Source code in repositories in the cloudops GitHub organisation.
  • Aptum's public-facing products, services, and infrastructure.

Not a vulnerability? Send network and content abuse reports – spam, phishing, malware, compromised hosts, denial-of-service traffic, and copyright or trademark claims – to abuse@aptum.com or through the abuse report form. These go to a different team and are handled under a different process.

Are you an Aptum customer with a security problem in your own environment? Raise a ticket through your normal support channel. That route is faster, and it is tied to your service agreement.

What to expect

  • We acknowledge every report within 5 business days.
  • We tell you whether we have reproduced the issue, and we keep you updated while we work on it.
  • We tell you when the issue is resolved.
  • We credit you when we publish a fix, if you want us to. Tell us the name or handle to use.

We do not publish target dates for a fix. How quickly we resolve a report depends on its severity, the systems it affects, and how much work the fix needs.

We do not operate a bug bounty programme and we do not pay for reports.

Testing limits

We want to hear about vulnerabilities you find. We do not authorise testing to find them.

Do not:

  • Test against live systems, production services, or customer environments.
  • Access, change, delete, or store data that is not your own.
  • Degrade or interrupt a service, including any form of denial-of-service test.
  • Use social engineering, phishing, or physical attacks against Aptum staff, customers, or facilities.
  • Move further into a system than you need to, once you have shown a vulnerability exists.
  • Publish details of the vulnerability before we have fixed it.

Aptum's Acceptable Use Policy applies to all use of our services and prohibits unauthorised scanning, access, and interference. This policy does not change it, and it does not commit Aptum in advance to any position on testing you carry out. Report what you find; do not go looking.

There aren't any published security advisories