Report it. We’ll work with you.
We’re a security company; we’d rather hear about a flaw from you than from an incident. If you’ve found a vulnerability in Cairn, this is how to tell us, and what we commit to in return.
Safe harbor
We will not pursue or support legal action against anyone who reports a vulnerability in good faith under this policy. If you make a genuine effort to follow it, act in good faith, and avoid privacy violations, data destruction, and service disruption, we consider your research authorized and we’ll work with you to understand and resolve the issue quickly.
How to report
Email security@cairnsecurity.com with enough detail for us to reproduce the issue: affected URL or component, a description of the vulnerability and its impact, and clear step-by-step reproduction. Proof-of-concept code, requests, or screenshots help. If you need to share sensitive material, say so and we’ll arrange an encrypted channel.
What we ask
Give us a reasonable window to investigate and remediate before any public disclosure. Only interact with accounts you own or have explicit permission to test. Don’t run automated scanning that degrades service, don’t access, modify, or delete other users’ data, and stop at the point where you’ve proven a vulnerability exists rather than pushing further into our systems.
What you can expect
We aim to acknowledge your report within three business days, confirm the issue and our assessment of severity, keep you updated as we work a fix, and credit you when it’s resolved if you’d like the recognition. We don’t currently run a paid bug-bounty program, so reports are handled on a coordinated-disclosure basis.
In scope
The Cairn platform and its client portals: platform.cairnsecurity.com, this marketing site, and the on-prem distribution. We’re most interested in anything affecting tenant isolation, authentication and authorization, data exposure, or the integrity of reports and evidence.
Out of scope
Reports from automated tools without a demonstrated, exploitable impact; missing security headers or best-practice suggestions with no concrete risk; social engineering, physical attacks, and denial-of-service; and vulnerabilities in third-party services we don’t control. When in doubt, send it anyway and let us make the call.
Reach the team directly.
Questions about our security posture, or want to run something by us before you dig in? We’re happy to hear from you.
← Back to the platform