Last updated: September 18, 2026
Unvertical maintains OpenCAS and the Unvertical premium packages. We welcome reports of security vulnerabilities in either.
Reporting
Email security@unvertical.com.
Encryption is optional but welcome. Our key is at unvertical.com/pgp.asc, fingerprint:
C4F9 E891 4068 AE50 8C82 CAB0 D2F2 63D3 DB9C 0EBD
Please include:
- affected component and version (or commit)
- steps to reproduce, ideally a minimal proof of concept
- the impact you believe it has
- whether anyone else has been told, and any disclosure date you intend to keep
Do not open a public issue or pull request for a suspected vulnerability. Email is our only intake channel.
Scope
In scope:
- OpenCAS codebase and its official release artifacts,
- Unvertical premium packages.
Out of scope:
- vulnerabilities in third-party dependencies (report them upstream and tell us if OpenCAS is exploitable because of one),
- volumetric denial of service,
- social engineering of Unvertical staff or users,
- reports generated by a scanner with no demonstrated impact.
What we commit to
- Acknowledge your report within 3 business days.
- Give an initial assessment, including whether we consider it a vulnerability and its severity, within 10 business days.
- Keep you updated at least every 14 days until the issue is closed.
- Publish an advisory and request a CVE for every confirmed vulnerability in a released version.
If we conclude a report is not a vulnerability, we will tell you why, and we will reconsider if you can show otherwise.
Disclosure
We ask for 90 days from your report before public disclosure. We will usually be faster. If a fix is ready sooner we release sooner. If the issue is already public, or is being actively exploited, we abandon the embargo and publish the impact and any workaround immediately, before a fix exists.
Fixes ship to OpenCAS and to premium packages on the same day, together with the advisory. We never ship a security fix silently.
If you set a disclosure date earlier than we can deliver a fix, we will publish what we have on that date and continue resolution in public.
Distribution maintainers and packagers may join a pre-notification list for embargoed advisories: write to security@unvertical.com. Embargo is typically 7 days and carries no right to deploy the fix before public release. We set the release date, taking your constraints into account.
Safe harbour
We will not pursue legal action against you for security research conducted in good faith under this policy, provided you avoid privacy violations, data destruction, and service degradation, use only accounts and data you own or have permission to test, and give us a reasonable chance to respond before disclosing.
Credit
We credit reporters in the advisory, the release notes, and the commit message. Before publication we will ask you how you want to be named, and show you the wording. Tell us if you would rather not be credited at all.
We do not currently run a bug bounty and cannot offer payment.