Disclosure

Findings go to the vendor first.

Reverse-engineering work regularly turns up defects in software we do not own. This page is what happens next. It is a policy rather than a preference: it does not change because a vendor is slow, unresponsive, or unhappy with what we found.

  1. day 0 report Reproduction, affected versions and our severity assessment go to the vendor.
  2. day 7 acknowledge We ask for confirmation of receipt. Silence does not stop the clock.
  3. vendor fix We stay available for questions and re-test a candidate fix on request.
  4. day 90 publish Advisory goes out, fixed or not. Extensions are granted for progress.

The clock

Day 0. The vendor receives the finding in full: affected component and versions, reproduction steps, what an attacker gains, and our assessment of severity. Nothing is held back from the people who have to fix it.

Day 7. We ask for confirmation of receipt. If none arrives we try a second channel — a security address, a maintainer, a national CERT. Silence does not stop the clock; it only means we publish without having been able to check the fix.

Day 90. The advisory goes public, whether or not a fix shipped. We extend that deadline for a vendor who is engaged and making progress, and we say so in the advisory when we do. An extension is granted for progress, never for silence.

Two things shorten it. If we find an issue already being exploited, the people at risk outrank the vendor's release schedule and we publish the mitigation immediately. If a fix is generally available sooner, so is the advisory — there is no reason to sit on it.

What we publish

Enough for an operator to decide whether they are exposed and what to do about it: affected component, affected versions, the class of defect, realistic impact, the fixed version, and the timeline of the disclosure itself — including the parts that reflect badly on us.

Not included: working exploit code. A proof-of-concept that a reader can point at production is a weapon, and shipping one does not make the advisory more true. Where a demonstration is genuinely needed to establish severity, it goes to the vendor and stops there.

What we never publish

  • Our own detection internals. Signature names, token identifiers, thresholds, bypass paths. A vendor that publishes its signatures is publishing a checklist for the other side. This is the same line our research writing holds.
  • Anything from a client engagement, without that client's written release. Work done for someone else belongs to them, findings included.
  • Personal data encountered incidentally. If research surfaces it, it is reported and deleted, not retained.

What we never do

  • We do not sell vulnerabilities. Not to brokers, not to buyers, not to the vendor. A finding is disclosed or it is withdrawn; it is not inventory.
  • We do not price silence. No payment is requested in exchange for withholding a finding, and the absence of a bug-bounty programme has no bearing on whether we report. Vendors without a budget get the same report as vendors with one.
  • We do not test systems we are not authorised to test. Research runs against software we obtain and operate ourselves, in our own environment. Live systems belonging to other people are examined only under a written engagement that says so.

Reporting something to us

Defects in our own software, or in a deployment we built, go to hello@lyphere.com. Include the version and how to reproduce it. You will get a human, not a ticket number.

We will not pursue legal action against anyone who reports a defect to us in good faith, keeps it confidential until it is fixed, and does not access, alter or destroy data belonging to anyone else while finding it. That protection is ours to give and we give it plainly.

Advisories

None published yet. Findings currently under embargo are not listed here, deliberately — naming an unannounced target is itself a disclosure, and the vendor is entitled to hear it before the internet does. Published advisories will appear here with their full timeline, including the dates we missed.