Security Vulnerability Disclosure Policy

Last updated: 11/09/2026

Classification: Public

We take the security of our products seriously. If you believe you've found a security vulnerability, or have evidence that a vulnerability is being actively exploited, we want to hear from you.


1. How to report

Contact: https://annex19.com/contact

PGP key: https://annex19.com/pgp-key

Fingerprint: 1270 9462 3E9C E228 6B36 177E 08BE 27EE 62D6 E8C3

Languages: English

Reporting sensitive vulnerabilities

If your report includes details of an unpatched or actively exploited vulnerability, please encrypt it using our PGP key before emailing it to us:

  1. Download our public key from the link above.

  2. Verify the fingerprint matches the one published on this page before trusting the key — don't rely solely on a key found elsewhere.

  3. Encrypt your report to that key.

  4. Send the encrypted message to via https://annex19.com/contact

Encryption is optional for general or low-sensitivity reports, but strongly recommended for anything involving an unpatched vulnerability or evidence of active exploitation.

Encrypting vs. signing: Encrypting your report to our public key ensures only we can read it. If you'd also like to prove the report came from you (and let us verify it hasn't been tampered with), you can additionally sign it with your own PGP key before encrypting. Signing is optional and only meaningful if you have your own key pair — it authenticates the sender, it does not replace encryption.

Please include as much of the following as you can:

  • Product and version affected

  • Description of the vulnerability

  • Steps to reproduce, or a proof of concept, if available

  • Any evidence suggesting the vulnerability is being actively exploited (e.g., logs, indicators of compromise)

  • Your contact details, if you'd like a response


2. What to expect

  • Acknowledgement of your report - Within [24–48 hours]

  • Initial review - Within [5–10 business days]

  • Follow-up or resolution update - As the assessment progresses

We review every report in good faith. Depending on the outcome of our assessment, a confirmed vulnerability may trigger further internal processes, including regulatory reporting where required by law.


3. Good-faith research

We do not currently offer a formal safe-harbour commitment or bug bounty program. We ask that researchers:

  • Avoid accessing, modifying, or deleting data that isn't their own

  • Avoid degrading the availability of our services

  • Give us a reasonable opportunity to investigate and address a report before any public disclosure

  • Not use automated scanning that could impact production systems without prior contact