At Windshift, security is a fundamental principle in the design, development, maintenance, and operation of our technology solutions.
We are committed to maintaining secure and reliable software, promoting responsible security research, and continuously improving the protection of our systems, applications, and users.
We value the contributions of the cybersecurity research community and encourage responsible vulnerability disclosure.
If you discover a potential security vulnerability in a project developed or maintained by Windshift, we encourage you to report it responsibly.
Do not disclose vulnerabilities through public GitHub issues, discussions, pull requests, or other public communication channels before an appropriate mitigation is available.
Instead, please report the vulnerability by email to:
When submitting a vulnerability report, please include:
- A clear description of the vulnerability.
- The affected project, component, and software version.
- Detailed steps to reproduce the issue.
- A proof of concept, when applicable.
- The potential security impact and affected assets.
- Any relevant logs, screenshots, or technical evidence.
- Suggested mitigation strategies, if available.
Please avoid including sensitive personal information, credentials, or confidential data in vulnerability reports unless strictly necessary and transmitted through an appropriate secure channel.
Windshift is committed to evaluating security reports with confidentiality, technical rigor, and appropriate prioritization.
Our vulnerability management process aims to:
- Acknowledge valid security reports within 48 hours.
- Perform an initial technical assessment of the reported issue.
- Determine the severity, impact, and affected components.
- Provide an initial remediation or mitigation plan within 7 days, depending on the severity and complexity of the issue.
- Coordinate security fixes and responsible disclosure with the reporting researcher when appropriate.
Remediation timelines may vary according to the technical complexity, severity, and potential impact of each vulnerability.
Critical vulnerabilities affecting confidentiality, integrity, or availability may receive expedited treatment.
Security updates are generally provided for the latest stable release of each actively maintained project.
Older releases, deprecated versions, experimental branches, and end-of-life components may not receive security fixes.
Users are strongly encouraged to keep their installations updated and follow the official release and security advisory channels of the respective project.
This security policy applies to software, applications, libraries, tools, and other technology projects officially developed and maintained by Windshift.
The following are generally considered within scope:
- Security vulnerabilities in officially maintained source code.
- Authentication and authorization weaknesses.
- Sensitive information disclosure.
- Cryptographic implementation vulnerabilities.
- Remote code execution and privilege escalation.
- Injection vulnerabilities.
- Insecure configurations directly related to our software.
- Other security weaknesses with demonstrable impact.
Third-party dependencies, external services, and software maintained by other organizations are generally outside the direct scope of this policy.
However, we welcome reports concerning vulnerabilities in third-party components that may affect the security of our projects.
We encourage security researchers to conduct their activities ethically, responsibly, and in accordance with applicable laws.
Researchers are expected to:
- Avoid unauthorized access to systems or information.
- Avoid activities that may disrupt service availability.
- Refrain from modifying, deleting, or exposing sensitive data.
- Limit testing to the minimum necessary to demonstrate a vulnerability.
- Maintain confidentiality until an appropriate disclosure timeline has been established.
- Cooperate with our security team during the investigation and remediation process.
This policy does not grant authorization to test systems, infrastructure, or services beyond the explicitly permitted scope of a given project.
Windshift supports coordinated vulnerability disclosure as a means of protecting users while enabling the cybersecurity community to advance security research.
When appropriate, vulnerability details may be disclosed through security advisories, release notes, or other official communication channels after a fix or suitable mitigation has been made available.
Disclosure timelines should be coordinated between the reporting researcher and our security team, considering the potential impact on affected users.
We recognize and appreciate the contributions of independent security researchers, developers, and members of the cybersecurity community who help improve the security of our technology solutions.
Researchers who responsibly report valid security vulnerabilities may receive acknowledgment in release notes, security advisories, or other official project communications, subject to their consent.
Researchers may also request to remain anonymous.
Windshift reserves the right to determine the appropriate form of recognition based on the nature and impact of each report.
Security is an ongoing process.
Windshift remains committed to continuous improvement, responsible innovation, secure software development, and collaboration with the global cybersecurity community.
Our objective is to develop technology that promotes trust, resilience, and security across the digital ecosystem.
Windshift