Skip to content
devwallssecurity
Fine dark filaments standing in close vertical rows
research

advisories, published under our own names

We give vendors ninety days from a reproducible report. After that we publish, whether or not there is a patch, because operators cannot mitigate a risk they have not been told about.

disclosure window
90 days
cves published
37
contact
disclosure@devwalls.com.ng
disclosure policy

ninety days, then we publish

We report to the vendor first, with a working proof-of-concept and enough detail to reproduce the issue without talking to us. The clock starts when we send it, not when someone replies.

If a vendor is engaged and shipping a fix, we will extend. If a vendor is silent, or is arguing about whether the bug exists, we will not. Where a fix is impossible — end-of-life hardware, for example — we publish the mitigation that operators can apply themselves.

Findings from client engagements are only published where the bug is in a third-party product rather than in the client’s own code, and the client is told before we contact the vendor.

disclosure@devwalls.com.ng
A dense city skyline at night, lit windows in red and amber

found something in one of our clients

If you have found an issue in a system we test, tell us and we will route it responsibly. We do not run a bounty, but we will credit you and keep you updated.