Sentrail
Security

Responsible disclosure

Effective
August 6, 2026
Version
2026.08
We build security tooling, so we expect to be held to the standard we hold others to. If you find a vulnerability in Sentrail, tell us and we will work the report properly. Good-faith research under this policy is authorized, and we will not pursue legal action for it.

01How to report

02What we commit to

03In scope

04Out of scope

05Rules of engagement

06Safe harbor

07Recognition and rewards

08Findings in customer systems

Basis for this document

Written to follow ISO/IEC 29147 (vulnerability disclosure) and the safe-harbor language pattern recommended by CISA's Binding Operational Directive 20-01 template and the disclose.io terms, with a machine-readable contact per RFC 9116. Provided for information; it is not legal advice.