Report a Security Vulnerability
Coordinated Vulnerability Disclosure for all Zedmos products and services.
Reporting a vulnerability
If you believe you have found a security vulnerability in a Zedmos product or service, email security@zedmos.com. Please include the affected product and version, steps to reproduce, and your assessment of the impact. Encrypted communication is available on request. A machine-readable version of this policy is published at /.well-known/security.txt.
What you can expect from us
We acknowledge your report within 3 business days, provide an initial assessment within 7 days, and keep you informed until the issue is resolved. If you wish, we will credit you once a fix has been published.
Coordinated disclosure
We ask that you do not publish details of a vulnerability before a fix is available to affected customers — normally within 90 days of your report. If a fix cannot be delivered within that window, we will agree on a disclosure timeline together.
Good-faith security research
We will not pursue legal action against good-faith security research, provided you do not access or modify third-party data, do not degrade our services, do not exfiltrate data, and do not exploit a vulnerability beyond what is necessary to demonstrate it.
Scope
- Zedmos for OPNsense (os-zedmos)
- Zedmos for pfSense (pfSense-pkg-zedmos)
- Zedmos Console (hosted and self-hosted)
- Hub services at zedmos.com / zedmos.de / zedmos.net
Security updates and support period
Every supported product release receives free security updates through the Zedmos package repositories for its published support period — at least five years from placing on the market, the minimum set by Art. 13(8) of Regulation (EU) 2024/2847 (Cyber Resilience Act). Every update remains available for at least ten years (Art. 13(9)) and is provided free of charge (Annex I Part II(8)). The Console surfaces available updates, and security-relevant fixes are flagged in the release notes.
Regulatory framework
Zedmos acts as a manufacturer within the meaning of Regulation (EU) 2024/2847 (Cyber Resilience Act). From 11 September 2026 we report actively exploited vulnerabilities and severe incidents to ENISA and the competent CSIRT via the single reporting platform, as required by Article 14.