security page hero image

Reporting a vulnerability

Email security@start9.com. Please include what you found, which product and version, and enough detail for us to reproduce it. If you have a proof of concept, send it — it saves everyone time.

Please give us a chance to fix the problem before you publish. We will not ask you to stay quiet indefinitely, and we will not ask you to sign anything.

What we will do

We are a small team. We would rather promise a response time we can keep than one that sounds better.

Safe harbour

If you research in good faith and follow this page, we will not pursue or support legal action against you, and we will say so if a third party tries. Good faith means: work only against your own devices and accounts, do not access, modify, or destroy anyone else's data, do not degrade our services for other people, and stop as soon as you have proved the point.

If you are unsure whether something is in bounds, ask us first at security@start9.com. We would rather answer the question than argue about it afterwards.

Scope

In scope: StartOS, StartWRT, StartTunnel, the Start CLI, the packaging SDK, the Start9 and Community registries, and our websites.

The Community Registry distributes software written by other people. If you find a vulnerability in one of those services, please report it to its authors — they can fix it and we cannot. Tell us as well if a Start9 packaging decision makes it worse, or if you think we should pull the package.

Security update period

Start9 provides security updates for each hardware product for at least five years from the date we stop selling that model. No device we have sold will get less than five years of security updates counted from the day it was bought.

When we discontinue a model we will publish its specific end date here, as a month and a year. We may extend a published date. We will never bring one forward.

StartOS and StartWRT are free and open source, and updates are free to everyone, on Start9 hardware or your own.

security.txt

Machine-readable contact details are at /.well-known/security.txt, per RFC 9116.