Skip to main content

Report a Security
Vulnerability

At Toolhive, we take the security of our platform and customers seriously.
We appreciate the responsible disclosure of security concerns.

We welcome feedback and vulnerability reports from security researchers, partners, and customers. If you believe you have discovered a security issue in our platform, please reach out via the secure channels below, and we will work to address it promptly.

 

What to include

When reporting a vulnerability, please include:
 

  • A clear description of the vulnerability and its potential impact
  • Detailed steps to reproduce the issue
  • Any relevant URLs, endpoints, or parameters involved
  • Your assessment of the severity
  • Any proof-of-concept code or screenshots

 

In scope

Our vulnerability disclosure programme covers all Toolhive-operated services, including:
 

  • Toolhivesolutions.com (Web application)
  • Toolhive solution respective CAM plugins and integrations to cloud
  • Toolhivesolutions.com website and its subdomains

Out of scope: third-party services, social engineering, denial of service attacks, and spam.

 

How reports are handled

Once a report is submitted:

  1. You will receive an acknowledgement within 2 business days
  2. Our security team will triage and investigate the issue
  3. We will provide updates on progress within 5 business days
  4. Once resolved, we will notify you and discuss disclosure timelines

We aim to resolve critical vulnerabilities within 30 days of confirmation.


Our commitment

We are committed to:

  • Responding promptly to all legitimate security reports
  • Keeping reporters informed throughout the remediation process
  • Crediting researchers who report valid vulnerabilities (with permission)
  • Not pursuing legal action against researchers acting in good faith
  • Coordinating public disclosure with the reporter

 

Safe harbour

To encourage responsible disclosure, we promise not to initiate legal actions against security researchers as long as they act in good faith, respect user privacy, avoid service degradation, and do not access or destroy sensitive database records.

 

Supported versions and updates

We provide security updates and patches for all current production-release versions of our cloud services. Local software deployments receive regular security revisions automatically or through scheduled updates.

 

We do not operate a bug bounty

While we highly value and acknowledge all contributions to the security of Toolhive, we do not currently operate a paid bug bounty program. We are happy to coordinate public attribution and credit on our security hall of fame.
 

Not a security issue?

If you are looking for general technical support, billing inquiries, or non-security product bugs, please visit our Help Center or submit a support ticket for faster routing to the correct service team.
 

Our security programme

Toolhive maintains a robust security lifecycle including automated security scanning in CI/CD, secure coding practices, regular third-party penetration audits, and strict adherence to strict compliance requirements.

 


 

Submit a report​

Fields marked as optional may be left blank to report anonymously. This form will send your report to toolhive.security@toolhivesolutions.com. We will only use your email to coordinate progress and clarify details.

Reporter
Any indication this is being actively exploited?