Third Party Index

Snapshot 10866

Document
Security page
URL
https://www.papercut.com/about/security-at-papercut/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
370814 bytes
SHA-256 (raw)
9fe9a0d7b19baad1a1ced65d5347a0f67387d925dc0c251fa56179a973443c5f
SHA-256 (normalized text)
45bdbde6d8b0595bfa77a673ca72d5099c70246189a006261bd63cee78641bcf

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security
PaperCut’s approach to security
This is your gateway to understanding our approach to security, both within our organization and across our products. Whether you're a sysadmin, a security professional, or simply someone who wants to understand how security works at PaperCut, this is the place to start.
August 8, 2025
Get proactive with notifications
Get security notifications covering our entire product range including critical updates, vulnerability alerts, and CVEs delivered directly from our team.
SUBSCRIBE
From the founder
My first real job in tech was as a sysadmin at a high school in the 90s. Staying one step ahead of students deep in the early hacker culture was one of the fun parts of the job, and it gave me the perspective to ensure that when PaperCut was built, it was designed defensively from day one.
While I still love the technical side and have contributed to open-source security tools like GhostTrap over the years, a key learning for me has been that great security isn’t just about the tech. It’s about fostering a learning culture, personally and across the entire organisation to keep up with a fast-moving landscape.
I’m committed to security and transparency, which is why I maintain our ISO 27001 certification and ensure our practices are available in the Trust Center. If you find an issue or have a concern, I genuinely want to hear about it.
Chris Dance
CEO and Co-Founder
PaperCut Software Pty Ltd
Our Security Resources & Documentation
We've compiled all the documentation you may need to run your security assessments and due diligence.
Our Trust Center
This is your central hub for all our security documentation. Here you can view and download our ISO 27001 certificate, security policies, recent third-party penetration test results, and the list of data processors.
Common Security Questions
Get quick answers to common security questions about PaperCut. Learn how we protect your data, ensure compliance, and safeguard your print environment.
White Papers
Dive deep into specific security topics with our expert-led white papers on data protection, compliance, and threat mitigation strategies in the print environment.
Our Trust Center
This is your central hub for all our security documentation. Here you can view and download our ISO 27001 certificate, security policies, recent third-party penetration test results, and the list of data processors.
Common Security Questions
Get quick answers to common security questions about PaperCut. Learn how we protect your data, ensure compliance, and safeguard your print environment.
White Papers
Dive deep into specific security topics with our expert-led white papers on data protection, compliance, and threat mitigation strategies in the print environment.
Security in Our Products and Services
If you've read this far, you're our kind of person... someone who sweats the details.
Data Handling &
Data Privacy
We adhere to a principle of data minimization, only collecting the data necessary for our services. All data is handled with the highest level of due care. For our SaaS products, all customer data is encrypted both in transit and at rest. We maintain a list of vetted sub-processors which is available on our Trust Center. You can also review our Privacy Policy for more details on how we handle your data.
Security Controls & Responsible Disclosure
Our security team maintains a robust control library that ensures the protection against vulnerabilities and threats. We have a clear Incident Response Plan to manage, mitigate, and communicate any issues. Our security vulnerability log provides a transparent record of all updates. If you discover a vulnerability, please report it via our responsible disclosure program.
Availability &
Business Continuity
We know that uptime is critical. Our cloud-hosted services are built for high availability and resilience, with robust backup and disaster recovery plans in place. Our backup strategy includes regular reviews to ensure the viability and integrity of all data. For real-time updates on our service status, you can visit our status page.
Data Handling &
Data Privacy
We adhere to a principle of data minimization, only collecting the data necessary for our services. All data is handled with the highest level of due care. For our SaaS products, all customer data is encrypted both in transit and at rest. We maintain a list of vetted sub-processors which is available on our Trust Center. You can also review our Privacy Policy for more details on how we handle your data.
Security Controls & Responsible Disclosure
Our security team maintains a robust control library that ensures the protection against vulnerabilities and threats. We have a clear Incident Response Plan to manage, mitigate, and communicate any issues. Our security vulnerability log provides a transparent record of all updates. If you discover a vulnerability, please report it via our responsible disclosure program.
Availability &
Business Continuity
We know that uptime is critical. Our cloud-hosted services are built for high availability and resilience, with robust backup and disaster recovery plans in place. Our backup strategy includes regular reviews to ensure the viability and integrity of all data. For real-time updates on our service status, you can visit our status page.
Latest security news
Security Bulletin 27 August 2026
This security bulletin addresses an unsafe dynamic class loading vulnerability in the database connector component of PaperCut NG/MF (CVE-2026-82078) and an authentication bypass in the web management interface component of PaperCut NG/MF (CVE-2026-81578). This is an active incident, and we will update this bulletin as our investigation progresses.
Security Bulletin 3rd August 2026
This security bulletin addresses insufficient brute-force protection in the PaperCut NG/MF login component (CVE-2026-8793) and a username enumeration timing discrepancy in the authentication component (CVE-2026-8794).
Want alerts?
Subscribe to our Security Newsletter to get critical security updates, vulnerability alerts, and CVE notifications directly from our team to your inbox.
Subscribe
Report a vulnerability
We believe in the power of community to make our products safer. If you discover a security vulnerability, please report it directly to our team via our responsible disclosure program. We value your partnership in keeping our products secure and will publicly recognize your contribution in our Hall of Fame after a successful disclosure.
Report a vulnerability
Ready to get started?
Compare our products or dive a little deeper into product solutions.
COMPARE OUR PRODUCTS TRY FOR FREE