Security
Reporting a vulnerability
Email security@start9.com. Please include what you found, which product and version, and enough detail for us to reproduce it. If you have a proof of concept, send it — it saves everyone time.
Please give us a chance to fix the problem before you publish. We will not ask you to stay quiet indefinitely, and we will not ask you to sign anything.
What we will do
- Acknowledge your report within 5 business days.
- Tell you whether we consider it a vulnerability, and why.
- Keep you updated while we work on it, and tell you when it ships.
- Credit you in the release notes if you want the credit, and leave you out of them if you don't.
We are a small team. We would rather promise a response time we can keep than one that sounds better.
Safe harbour
If you research in good faith and follow this page, we will not pursue or support legal action against you, and we will say so if a third party tries. Good faith means: work only against your own devices and accounts, do not access, modify, or destroy anyone else's data, do not degrade our services for other people, and stop as soon as you have proved the point.
If you are unsure whether something is in bounds, ask us first at security@start9.com. We would rather answer the question than argue about it afterwards.
Scope
In scope: StartOS, StartWRT, StartTunnel, the Start CLI, the packaging SDK, the Start9 and Community registries, and our websites.
The Community Registry distributes software written by other people. If you find a vulnerability in one of those services, please report it to its authors — they can fix it and we cannot. Tell us as well if a Start9 packaging decision makes it worse, or if you think we should pull the package.
Security update period
Start9 provides security updates for each hardware product for at least five years from the date we stop selling that model. No device we have sold will get less than five years of security updates counted from the day it was bought.
When we discontinue a model we will publish its specific end date here, as a month and a year. We may extend a published date. We will never bring one forward.
StartOS and StartWRT are free and open source, and updates are free to everyone, on Start9 hardware or your own.
security.txt
Machine-readable contact details are at /.well-known/security.txt, per RFC 9116.