A real disclosure channel, a real response process.
Security software is judged by how it handles the vulnerabilities it will inevitably have. B5 Secure operates a coordinated vulnerability disclosure process and a documented incident-response and patch posture — the practices that separate a credible security vendor from a hopeful one.
The question is not whether — it is how you respond.
Every nontrivial software product will have vulnerabilities. What a regulated buyer needs to know is that there is a way to report them, a process to triage and fix them, and a commitment to communicate. B5 provides a clear channel and a documented response posture so that, when something is found, the path from report to patch is known in advance.
How disclosure and response work at B5.
A predictable, documented path from report to remediation.
Coordinated disclosure channel
Report security issues to security@b5secure.com. We acknowledge, triage, and coordinate disclosure on a responsible timeline.
Triage and severity
Reports are triaged and assigned severity, with target timelines tied to impact — not left to ad-hoc handling.
Patch and support SLA
A documented commitment to remediate and release fixes, with clear support and patch windows.
Customer notification
Affected customers are notified with the information needed to assess exposure and apply remediations.
In-boundary advantage
Because B5 operates no endpoint holding your data, an incident’s scope is the library and its pipeline — not a breach of a vendor cloud full of customer records.
Provenance for response
SBOM and provenance let both sides reason precisely about which releases are affected and which are not.
How reviewers use this.
Known path to report
A published channel and process means your researchers and team know exactly how a finding will be handled.
Bounded incident scope
No B5-operated data cloud means an incident cannot be a breach of your records held by B5.
Documented commitments
A written disclosure and patch posture is the evidence vendor-risk review expects.
Honest about scope and responsibility.
B5 responds for what B5 ships.
This process covers vulnerabilities in the B5 libraries and pipeline. Because B5 runs inside your environment and holds no customer data, B5 is not a holder of your records to be breached — the response scope is the software supply chain, and the in-boundary model keeps it that way.
Report responsibly. Get a real response.
Security researchers and customers can reach our team at security@b5secure.com. Review the full disclosure and response posture in the Trust Center.