Vulnerability disclosure policy
1. Purpose
Purde Software welcomes reports from security researchers, customers, and users who identify potential vulnerabilities in our products and services. This policy explains how to report, what to expect from us, and the protections that apply to researchers acting in good faith.
2. Scope
This policy covers:
Purde Software's apps published on the Atlassian Marketplace — for Confluence Cloud and Confluence Data Center.
Purde Software's customer-facing services hosted under the
purde.de,purde.euandpurde-software.atlassian.netdomains.
The following are out of scope for this policy:
Vulnerabilities in Atlassian, AWS, Heroku, or other upstream platforms (please report these directly to the relevant vendor).
Findings that require a customer to misconfigure their own Confluence instance.
Denial-of-service, volumetric, or social-engineering attacks against Purde Software, its contributors, or its customers.
3. How to report
Use one of the following channels and clearly mark the report as a security disclosure:
Service Desk: https://purde-software.atlassian.net/servicedesk/customer/portal/2 — create a ticket and set type to "Security".
Email: support@purde.de — use subject prefix
[SECURITY].
Please include:
the affected product and version;
a concise description of the issue and its potential impact;
step-by-step reproduction details, including any proof-of-concept code;
your assessment of severity (CVSS v3.1 base score if possible);
whether you have shared the finding with any third party;
how you would like to be credited (or that you prefer to remain anonymous).
4. Our commitments to you
Acknowledgement within 2 business days of receiving the report.
Triage and initial assessment within 5 business days.
Status updates at least every 10 business days while the report is open.
Remediation timelines per SLA — security vulnerabilities table, based on CVSS v3.1 severity.
Credit in the resolution note where you wish to be identified, unless the report contains information we are required to withhold.
5. Coordinated disclosure
We follow a coordinated disclosure approach:
Please give us a reasonable opportunity to investigate and remediate before public disclosure — typically 90 days from acknowledgement, or sooner if a fix is released earlier.
Where a vulnerability requires action by Atlassian or another upstream vendor, the timeline may be extended in coordination with that vendor.
We will keep you informed of our progress and let you know before any planned public statement that names the issue or the reporter.
6. Safe harbor
If you act in good faith under this policy, Purde Software will not pursue legal action against you, nor request that authorities do so, in connection with your research, provided you:
limit testing to the in-scope assets in §2;
do not access, modify, or delete data beyond what is necessary to demonstrate the vulnerability;
do not disrupt the service or other users;
do not exploit the vulnerability for any purpose other than verifying its existence;
do not disclose the vulnerability publicly before the coordinated-disclosure window has closed;
comply with applicable law throughout.
This safe harbor does not extend to attacks on third parties (Atlassian, AWS, Heroku, customer instances) or to any activity outside the scope of this policy.
7. Rewards
We do not currently operate a bug-bounty program. We may, at our discretion, offer a token of appreciation for high-impact reports.
8. Related documents
9. Version history
Version | Date | Changes |
|---|---|---|
1.0 | May 31, 2026 | Initial publication. |