• Services
    • Penetration Testing
      Web, Mobile, AI/LLM, API & Cloud
    • Adversary Simulation
      Red teaming & Purple teaming
    • M365 & Google Workspace Audit
      Cloud productivity security review
    • Product Security Assessment
      Holistic product security review
    • vCISO & Advisory
      Strategic security leadership
    • Platform
    • Overview
      Explore our security platform
    • PTaaS
      Penetration Testing as a Service
    • Integrations
      Connect with your tools
    • Industries
    • SaaS & Technology
    • Banking & Fintech
    • Healthcare & Life Sciences
    • E-Commerce & Retail
    • Energy & Utilities
    • Company Size
    • Startups
    • Mid-Market
    • Enterprise
    • Frameworks & Risks
    • SOC 2
    • ISO 27001
    • PCI DSS
    • HIPAA
    • GLBA
    • DORA
    • NIS2
    • Trusted Partner Network
    • GDPR
    • TISAX
    • DiGA
    • Cyber Due Diligence for M&A
    • Resources
    • Blog
      Insights and security news
    • Guides & Reports
      Calculate your pentest ROI
    • Testing Comparison Guide
      PTaaS vs Pentest vs Bug Bounty
    • ROI Calculator
      Calculate your Pentest ROI
    • Labs
      Security research and tools
    • Company
    • About Us
    • Partner Program
    • Careers
    • Security & Trust
    • Contact
  • Pricing
Talk to an Expert

Vulnerability Disclosure

Vulnerability Disclosure Policy

Blaze supports coordinated vulnerability disclosure. This policy explains how to report a security issue affecting Blaze and how we coordinate disclosure when our researchers find vulnerabilities in third-party products.

Report a vulnerability affecting Blaze

Email [email protected] with the subject “Vulnerability disclosure”. For sensitive findings, ask us for a suitable secure channel before sending technical details or evidence. Include the affected Blaze-operated website or service, a description of the issue and potential impact, clear steps to reproduce it, minimal evidence, and a way to contact you if you want a response. Include relevant dates or prerequisites when useful. Remove passwords, access tokens, and unrelated personal data. Do not publish sensitive findings in a public GitHub issue.

Scope and responsible testing

Reports about systems operated by Blaze are welcome. Client systems and third-party services are outside this policy, even when Blaze has assessed or linked to them. Reporting a vulnerability does not itself authorize testing. If you are uncertain about ownership, scope, or permission, contact us before proceeding.

Keep any testing within the authorization you have. Avoid disruption, denial of service, social engineering, persistence, changes to data, lateral movement, and access to other people's accounts. Use the minimum evidence needed to demonstrate the issue. If you encounter personal data, credentials, or other sensitive information, stop further access and report the exposure without copying or retaining more than necessary.

What happens after a report

We review the information, assess whether it affects Blaze, and may ask for clarification or additional reproduction details. Where an issue is confirmed, we assess its impact and the appropriate remediation. If you provide contact details, we aim to keep you informed of relevant progress. The time needed depends on the issue, its complexity, and any third parties involved.

Please coordinate public disclosure with us so we can address the issue and reduce risk to affected people. This policy does not offer a bug bounty or guarantee a reward. It cannot authorize testing of systems owned by others.

Vulnerabilities Blaze finds in third-party products

Our researchers seek an appropriate security contact for the vendor or maintainer and share enough information to reproduce and assess the issue, using a suitable secure channel where available. If the initial report receives no response, we normally follow up after seven days and try other appropriate contact channels. We may seek help from a coordination body such as CERT/CC when direct coordination is unsuccessful or several parties are affected. An email that does not bounce is not proof that the report reached the right team.

Disclosure timing

Our usual target is coordinated disclosure approximately 45 days after the initial private report to the vendor. We may extend that period, commonly up to 90 days, when the vendor is making meaningful progress and additional time is justified. Timing depends on severity, evidence of exploitation, available mitigations, and the work needed to release and deploy a fix. Active exploitation may justify earlier disclosure; complex remediation may justify a longer period.

If a vendor does not respond or a fix is unavailable by the agreed date, we assess whether publication will help users protect themselves and what information can be released without unnecessary risk. Where practicable, we notify the vendor of the intended publication date beforehand. Publication is not automatic on a fixed day.

Advisories and technical detail

An advisory may describe affected versions, impact, remediation or workarounds, the disclosure timeline, and research credits. We include technical detail or proof-of-concept material when it helps users and maintainers understand or verify the issue, while considering misuse risk. We do not publish confidential client information or unnecessary personal data. Findings from client engagements remain subject to applicable confidentiality and disclosure terms.

Historical advisories and Blaze's original 2016 policy: https://github.com/blazeinfosec/advisories. This page is our current policy for new reports and coordination.

Last updated: 28 September 2026.

Ready to see how Blaze would attack your app?

Get a tailored testing plan and timeline in less than 24 hours.

Get Secured Today
Ask about Blaze
  • Services
  • Penetration Testing
  • Adversary Simulation
  • Product Security Assessment
  • vCISO & Advisory
  • Resources
  • Blog
  • Guides & Reports
  • Testing Comparison GuideROI Calculator
  • Labs
  • Company
  • About Us
  • Partner Program
  • Careers
  • Security & Trust
  • Contact
  • Pricing
  • Follow Us

© 2026 Blaze Information Security. All rights reserved.

Privacy PolicyTerms of ServiceOmbudsmanVulnerability DisclosureData ProtectionImprint