Snapshot 10866
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security PaperCut’s approach to security This is your gateway to understanding our approach to security, both within our organization and across our products. Whether you're a sysadmin, a security professional, or simply someone who wants to understand how security works at PaperCut, this is the place to start. August 8, 2025 Get proactive with notifications Get security notifications covering our entire product range including critical updates, vulnerability alerts, and CVEs delivered directly from our team. SUBSCRIBE From the founder My first real job in tech was as a sysadmin at a high school in the 90s. Staying one step ahead of students deep in the early hacker culture was one of the fun parts of the job, and it gave me the perspective to ensure that when PaperCut was built, it was designed defensively from day one. While I still love the technical side and have contributed to open-source security tools like GhostTrap over the years, a key learning for me has been that great security isn’t just about the tech. It’s about fostering a learning culture, personally and across the entire organisation to keep up with a fast-moving landscape. I’m committed to security and transparency, which is why I maintain our ISO 27001 certification and ensure our practices are available in the Trust Center. If you find an issue or have a concern, I genuinely want to hear about it. Chris Dance CEO and Co-Founder PaperCut Software Pty Ltd Our Security Resources & Documentation We've compiled all the documentation you may need to run your security assessments and due diligence. Our Trust Center This is your central hub for all our security documentation. Here you can view and download our ISO 27001 certificate, security policies, recent third-party penetration test results, and the list of data processors. Common Security Questions Get quick answers to common security questions about PaperCut. Learn how we protect your data, ensure compliance, and safeguard your print environment. White Papers Dive deep into specific security topics with our expert-led white papers on data protection, compliance, and threat mitigation strategies in the print environment. Our Trust Center This is your central hub for all our security documentation. Here you can view and download our ISO 27001 certificate, security policies, recent third-party penetration test results, and the list of data processors. Common Security Questions Get quick answers to common security questions about PaperCut. Learn how we protect your data, ensure compliance, and safeguard your print environment. White Papers Dive deep into specific security topics with our expert-led white papers on data protection, compliance, and threat mitigation strategies in the print environment. Security in Our Products and Services If you've read this far, you're our kind of person... someone who sweats the details. Data Handling & Data Privacy We adhere to a principle of data minimization, only collecting the data necessary for our services. All data is handled with the highest level of due care. For our SaaS products, all customer data is encrypted both in transit and at rest. We maintain a list of vetted sub-processors which is available on our Trust Center. You can also review our Privacy Policy for more details on how we handle your data. Security Controls & Responsible Disclosure Our security team maintains a robust control library that ensures the protection against vulnerabilities and threats. We have a clear Incident Response Plan to manage, mitigate, and communicate any issues. Our security vulnerability log provides a transparent record of all updates. If you discover a vulnerability, please report it via our responsible disclosure program. Availability & Business Continuity We know that uptime is critical. Our cloud-hosted services are built for high availability and resilience, with robust backup and disaster recovery plans in place. Our backup strategy includes regular reviews to ensure the viability and integrity of all data. For real-time updates on our service status, you can visit our status page. Data Handling & Data Privacy We adhere to a principle of data minimization, only collecting the data necessary for our services. All data is handled with the highest level of due care. For our SaaS products, all customer data is encrypted both in transit and at rest. We maintain a list of vetted sub-processors which is available on our Trust Center. You can also review our Privacy Policy for more details on how we handle your data. Security Controls & Responsible Disclosure Our security team maintains a robust control library that ensures the protection against vulnerabilities and threats. We have a clear Incident Response Plan to manage, mitigate, and communicate any issues. Our security vulnerability log provides a transparent record of all updates. If you discover a vulnerability, please report it via our responsible disclosure program. Availability & Business Continuity We know that uptime is critical. Our cloud-hosted services are built for high availability and resilience, with robust backup and disaster recovery plans in place. Our backup strategy includes regular reviews to ensure the viability and integrity of all data. For real-time updates on our service status, you can visit our status page. Latest security news Security Bulletin 27 August 2026 This security bulletin addresses an unsafe dynamic class loading vulnerability in the database connector component of PaperCut NG/MF (CVE-2026-82078) and an authentication bypass in the web management interface component of PaperCut NG/MF (CVE-2026-81578). This is an active incident, and we will update this bulletin as our investigation progresses. Security Bulletin 3rd August 2026 This security bulletin addresses insufficient brute-force protection in the PaperCut NG/MF login component (CVE-2026-8793) and a username enumeration timing discrepancy in the authentication component (CVE-2026-8794). Want alerts? Subscribe to our Security Newsletter to get critical security updates, vulnerability alerts, and CVE notifications directly from our team to your inbox. Subscribe Report a vulnerability We believe in the power of community to make our products safer. If you discover a security vulnerability, please report it directly to our team via our responsible disclosure program. We value your partnership in keeping our products secure and will publicly recognize your contribution in our Hall of Fame after a successful disclosure. Report a vulnerability Ready to get started? Compare our products or dive a little deeper into product solutions. COMPARE OUR PRODUCTS TRY FOR FREE