advisories, published under our own names
We give vendors ninety days from a reproducible report. After that we publish, whether or not there is a patch, because operators cannot mitigate a risk they have not been told about.
- disclosure window
- 90 days
- cves published
- 37
- contact
- disclosure@devwalls.com.ng
ninety days, then we publish
We report to the vendor first, with a working proof-of-concept and enough detail to reproduce the issue without talking to us. The clock starts when we send it, not when someone replies.
If a vendor is engaged and shipping a fix, we will extend. If a vendor is silent, or is arguing about whether the bug exists, we will not. Where a fix is impossible — end-of-life hardware, for example — we publish the mitigation that operators can apply themselves.
Findings from client engagements are only published where the bug is in a third-party product rather than in the client’s own code, and the client is told before we contact the vendor.
found something in one of our clients
If you have found an issue in a system we test, tell us and we will route it responsibly. We do not run a bounty, but we will credit you and keep you updated.
