Skip to content
xenXDRby FluenceSecurity
PricingDocs
EN·PL
Sign inBook a demo
  1. XenXDR
  2. Legal
  3. Vulnerability disclosure policy

Vulnerability disclosure policy

How to report a security issue in XenXDR, this website or a hosted tenant, what to expect from us, and our safe harbour for good-faith researchers.

Version 1.0Last updated 2026-09-15

On this page

  1. 1Our commitment
  2. 2Scope
  3. 3Rules of engagement
  4. 4How to report
  5. 5What you can expect
  6. 6Coordinated disclosure
  7. 7Safe harbour
  8. 8Changes

Our commitment

FluenceSecurity builds a security product, so we take reports about our own security seriously. If you believe you have found a vulnerability in anything we operate or ship, we want to hear from you, and we will work with you to understand and fix it.

Scope

This policy covers:

  • the XenXDR platform, including the console, the ingest pipeline, the detection and automation engines and the customer portal, in the current release and the one before it;
  • the XenXDR endpoint agent for Windows and Linux;
  • hosted tenants under the xdr.fluencesecurity.com domain operated by FluenceSecurity;
  • this website, xdr.fluencesecurity.com, and the documentation.

Out of scope:

  • self-hosted deployments operated by customers, unless the issue is in the software itself. Report issues with a customer's deployment to that customer;
  • third-party services we use, such as Cloudflare, Okta or Microsoft; report those to the vendor;
  • findings that require physical access to a device, social engineering of our staff or customers, or denial of service;
  • missing security headers, version disclosure or similar findings without a demonstrated impact;
  • reports produced solely by automated scanners without validation.

Rules of engagement

Please:

  • test only against systems you own or are authorised to test. For hosted tenants, ask us for a test tenant rather than testing a customer's;
  • stop as soon as you have enough evidence to demonstrate the issue. Do not read, modify or exfiltrate data that is not yours;
  • do not degrade or disrupt a service, and do not use automated tools at volume against production systems;
  • keep the details confidential until we have fixed the issue and agreed on publication;
  • do not demand payment as a condition of disclosure.

How to report

Email security@fluencesecurity.com. If you want to encrypt your report, ask us for our current PGP key in a first message. Include:

  • what you found and where, with the product version or the URL;
  • steps to reproduce, and a proof of concept if you have one;
  • the impact as you understand it;
  • how you would like to be credited, or that you prefer not to be.

Our security.txt file at /.well-known/security.txt points to this policy.

What you can expect

  • An acknowledgement within 2 business days.
  • An initial assessment of severity and a first response about our plan within 10 business days.
  • Regular updates while we work on a fix, and a note when it ships.
  • A fix for confirmed vulnerabilities, prioritised by severity; critical issues in hosted tenants are addressed as an incident.
  • Credit in our release notes if you wish.

We do not run a paid bug bounty programme at this time.

Coordinated disclosure

We ask for 90 days from acknowledgement before public disclosure, or until a fix has shipped to affected customers, whichever comes first. If we need more time, we will explain why and agree a date with you. We will not ask you to withhold disclosure indefinitely.

Safe harbour

If you act in good faith and follow this policy, FluenceSecurity will not pursue legal action against you for your research, will not report you to law enforcement for it, and will consider your activity authorised for the purposes of the Polish Penal Code provisions on unauthorised access and of the Computer Misuse-type laws of other jurisdictions to the extent we are able. If a third party takes action against you for research covered by this policy, we will make it known that you acted with our authorisation. This safe harbour does not cover actions that go beyond the rules above.

Changes

We may update this policy as the programme matures. The version and date at the top identify the current text.

Questions about this document?

Write to legal@fluencesecurity.com or privacy@fluencesecurity.com for privacy matters.

xenXDRby FluenceSecurity

A FluenceSecurity product
Made in Gdańsk, Poland

  • GitHub
  • LinkedIn
  • X

Platform

  • Platform overview
  • SIEM and search
  • Endpoint agent
  • Detections
  • AI triage
  • Playbooks and response
  • Alerts, cases and reports
  • Multi-tenancy and access
  • Customer portal
  • Integrations

Solutions

  • For security teams
  • For MSSPs
  • Managed SOC by FluenceSecurity

Resources

  • Documentation
  • Why XenXDR
  • Security and trust
  • Changelog
  • Pricing

Company

  • fluencesecurity.com
  • About FluenceSecurity
  • MDR service
  • Blog
  • Contact

Legal

  • Privacy policy
  • Cookie policy
  • Website terms
  • Software licence terms
  • Data processing
  • Service levels
  • Company details
  • Accessibility
  • Vulnerability disclosure
  • Subprocessors
© 2026 FluenceSecurity. All rights reserved.Sigma, Splunk, Okta, Microsoft, Fortinet and other marks belong to their respective owners.
EN·PL