Security Policy & Responsible Disclosure
B5 Secure’s security program and responsible-disclosure process, including scope, safe harbor, and how to report a vulnerability.
1.Our Security Program
We follow a secure development lifecycle for the B5 Secure software, including code review, dependency management, and testing, and we publish the status of our certifications and assurance programs on our Trust Center. Cryptographic key custody, where applicable to a deployment, is designed to use validated hardware security modules. Because the software runs inside our customers’ environments, customers retain control of their own infrastructure, configuration, and data.
2.Reporting a Vulnerability
If you believe you have found a security vulnerability in the B5 Secure software, the Site, or our services, please report it to security@b5secure.com. Include a description of the issue, the affected component or URL, steps to reproduce, and any proof-of-concept. Please give us a reasonable opportunity to investigate and remediate before any public disclosure.
3.Safe Harbor
We will not pursue or support legal action against researchers who, in good faith, comply with this Policy; access only their own data or test data; avoid privacy violations, data destruction, and service degradation; and do not exfiltrate data beyond the minimum needed to demonstrate the issue. If legal action is initiated by a third party against you for activity conducted under this Policy, we will make this authorization known.
4.Scope and Exclusions
In scope: the B5 Secure software, b5secure.com, and B5 Secure–operated developer services. Out of scope: third-party services we do not control, volumetric denial-of-service testing, social-engineering of our staff or customers, and physical attacks. Findings that require unrealistic user interaction or that have no security impact may be deemed informational.
5.Our Commitments
We will acknowledge your report, work to validate and triage it promptly, keep you informed of remediation progress, and credit you for the discovery if you wish. We coordinate disclosure timelines with reporters and aim to resolve valid issues on a reasonable, risk-based schedule.
6.Contact
Security reports: security@b5secure.com. General security questions may also be directed there. B5 SECURE LLC, PO Box 1410, Menlo Park, CA 94026-1410.
Download PDF These terms are accepted by your access to and use of the B5 Secure website and materials.