Free Trial

How to report a vulnerability

Anyone may report an ECLAIR vulnerability without a login, payment or maintenance contract.

Primary security contact: security@bugseng.com

BUGSENG also uses this address as the sender and reply address for direct security notices to affected users. Known impacted users receive those notices by email, directly or through a documented distributor route. This page is not a public case tracker, and users do not receive an email for every internal action or Single Reporting Platform stage.

Backup security contact: support@bugseng.com
Last-resort security contact: emergency.bugseng@gmail.com

Please include, when known:

  • the affected ECLAIR version, build, platform and configuration;
  • the third-party component and version, if relevant;
  • steps to reproduce or other evidence;
  • observed or potential impact;
  • whether exploitation has been observed; and
  • a safe way to contact you.

Do not send passwords, private keys, critical data or exploit material through ordinary email.


Coordinated Vulnerability Disclosure policy

BUGSENG Product Security Incident Response Team and reporter work together to reduce harm before public disclosure.

BUGSENG will:

  • acknowledge receipt;
  • investigate relevant ECLAIR versions, including legacy and out-of-maintenance releases;
  • provide status updates where practical;
  • coordinate a correction, mitigation and disclosure where appropriate.

Reporter information will be handled under the BUGSENG Product-Security and Privacy Policy.

Download the policy

We ask reporters to:

  • act in good faith and avoid privacy violations, service disruption, destruction of data and access beyond what is necessary to demonstrate the issue;
  • give BUGSENG a reasonable opportunity to investigate and protect users before publication;
  • keep any sensitive detail confidential while coordination is active; and
  • comply with applicable law.