Xona’s engineering team will review all reports that are submitted directly to us. After you submit your report via email, you’ll receive an automatic acknowledgement that we received your report. We do not issue bug bounties for reporting vulnerabilities.
For the protection of our customers, Xona doesn’t disclose or discuss security issues until our investigation is complete and any necessary updates are generally available (30-60 days).
Xona uses our product release notes to publish information about security fixes in our products and to publicly credit people or organizations that have reported security issues to us.
Xona will also assign a CVE number to the reported vulnerability and provide details of the security issue/fix on our Security Advisories Page.
Please make sure that you include the information covered above. If your report doesn’t include enough information to allow us to reproduce the issue, we may not be able to accept your report. Do not including customer specific or PII related information in your reports.