Product Security and Vulnerability Disclosure
Last reviewed: 9th September 2026. This policy is reviewed at least annually.
Disguise takes the security of our products, services and websites seriously. If you believe you have found a security vulnerability in a disguise product, cloud service or website, we want to hear from you.
Report a vulnerability
This mailbox is our single point of contact for security vulnerability reports and is monitored by the disguise security team.
We accept reports from anyone — customers, partners, researchers and members of the public. You do not need an existing relationship with disguise to report an issue, and you do not need to identify yourself if you would rather not. You can write to us in English.
If you would prefer not to use email, you can write to us at 88-89 Blackfriars Rd, London SE1 8HA, marked for the attention of the Security Team, and we will respond using the contact details you give us.
If you are a disguise customer and your report concerns an incident affecting your own deployment rather than a flaw in the product, please also raise it through your normal support channel so that it is tracked against your account.
What to include in a report
The more detail you can give us, the faster we can validate and fix the issue. Where possible, please tell us:
- The product, service or URL affected, and the version or build number.
- The type of issue — for example remote code execution, authentication bypass, information disclosure or privilege escalation.
- Step-by-step instructions to reproduce it, including any configuration required.
- Proof-of-concept code, screenshots or packet captures, if you have them.
- The impact you believe the issue has, and any conditions or mitigations that limit it.
- Whether the issue is, to your knowledge, already public or already being exploited.
- How you would like to be credited, if at all, and whether you intend to publish.
Please do not include live customer data, credentials or personal data in your report. Describe what you found instead.
What you can expect from us
| Stage | Our target |
| Acknowledgement of your report | Within 3 business days |
| Initial validity and severity assessment | Within 10 business days |
| Progress updates while the issue is open | At least every 14 days |
| Agreement on a coordinated disclosure date | Within 30 days of validation |
We assess severity using CVSS. From the point a report is validated, our remediation targets are:
| Severity | Target for a fix or documented mitigation |
| Critical | 30 days |
| High | 60 days |
| Medium | 90 days |
| Low | Next scheduled release |
Where a vulnerability is being actively exploited, or where an incident is affecting the security of our products, we act immediately and do not wait for these targets.
We will tell you when the issue is fixed, and we will let you know if we decide the report is not a vulnerability, and why.
Coordinated disclosure
We ask that you give us a reasonable opportunity to fix an issue before you make it public. Our default position is 90 days from the date we acknowledge your report, and we will work with you to agree a date that fits the complexity of the fix. We may ask for more time where a fix requires coordination with third parties or with customers who need a maintenance window. We may also publish sooner if the issue is already public or under active exploitation.
With your permission, we will credit you by name or handle in the advisory. We do not currently operate a paid bug bounty programme.
Testing: what is and is not in scope
In scope:
- disguise product software and firmware, on hardware you own or are licensed to use.
- disguise-operated cloud services and public websites under disguise.one.
Out of scope:
- Third-party services we do not operate, including anything hosted on a domain we do not control.
- Findings from automated scanners without a demonstrated, exploitable impact.
- Social engineering of disguise staff, customers or suppliers, and physical attacks on disguise premises or on customer sites.
- Denial-of-service testing, load testing, and anything that degrades service for others.
- Reports concerning only missing best-practice headers, TLS configuration preferences or version disclosure, with no demonstrated impact.
Please do not:
- Access, modify, delete or exfiltrate data that is not your own. If you encounter customer data, stop, and tell us in your report.
- Disrupt a live production show, installation or broadcast environment.
- Use a vulnerability beyond the minimum needed to demonstrate it.
- Demand payment in exchange for withholding a report.
If you follow this policy in good faith, disguise will not initiate or support legal action against you in relation to your research, and we will make that position clear if a third party raises a concern with us. This is a statement of intent by disguise; it cannot waive the rights of our customers or of third parties, and it does not authorise you to test systems you do not own.
Regulatory reporting
disguise reports actively exploited vulnerabilities and severe security incidents affecting our products with digital elements to the relevant national CSIRT and to ENISA, through the EU Single Reporting Platform, in line with Article 14 of Regulation (EU) 2024/2847 (the Cyber Resilience Act). Where a report you send us falls into that category, we may need to notify the authorities within 24 hours of becoming aware of it.
We will not share your identity with authorities or with third parties without your consent unless we are legally required to do so, and we will tell you if that happens.
Where a vulnerability or incident affects users of our products, we will inform affected users and, where appropriate, all users, together with any mitigating measures they can take.
Product support periods
Reports against products past the end of their support period will still be assessed, but a fix may only be available in a supported release.