Third Party Index

Snapshot 48516

Document
Security advisories
URL
https://licensespring.com/vulnerability-disclosure-policy
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
81229 bytes
SHA-256 (raw)
1c3dbb1e156ad1582308d298a2cf27ac5d74850c2d388ac4eccf661a590ca5ac
SHA-256 (normalized text)
54d05825d9d1a5ee670e23a92415798ff06c8f619bad92acaa304263a423fb3b

Normalized text

Scripts and page chrome removed; this is what change detection compares.

LicenseSpring takes the security of its platform, APIs, SDKs, and tooling seriously. We value the work of security researchers and welcome reports of vulnerabilities in our products and services. This page describes what is in scope, how to report a finding, what you can expect from us, and the protections we offer to researchers who act in good faith.
This policy is LicenseSpring's coordinated vulnerability disclosure (CVD) policy and serves as our single point of contact for vulnerability reports under the EU Cyber Resilience Act (Regulation (EU) 2024/2847).
Scope
In scope
The following LicenseSpring-operated systems and software are in scope:
LicenseSpring Platform (saas.licensespring.com) and the Management API
License API (api.licensespring.com) and all licensing endpoints
User Portal and Offline / Air-gapped Portal
Official SDKs and client libraries published by LicenseSpring (C++, C#/.NET, Java, Python, Go, JavaScript/TypeScript, Swift, and others)
Floating Server and other on-premise components distributed by LicenseSpring
LicenseSpring MCP server and official integrations
Public websites operated by LicenseSpring (licensespring.com, docs.licensespring.com)
If you are unsure whether something is in scope, report it anyway. We would rather receive a report we cannot act on than miss a real issue.
Out of scope
The following are not eligible under this policy:
Vulnerabilities in third-party services, hosting providers, or dependencies that LicenseSpring does not control. Please report those to the responsible vendor. If a third-party issue affects LicenseSpring users, we still want to know.
Vulnerabilities in applications built by customers using our SDKs, where the root cause is the customer's implementation rather than the SDK itself.
Denial of service, volumetric attacks, load testing, or any activity that degrades service for other users.
Social engineering, phishing, or physical attacks against LicenseSpring staff, customers, or facilities.
Reports from automated scanners without a demonstrated, reproducible impact.
Missing security headers, TLS configuration notes, or similar best-practice findings without an exploitable impact.
Clickjacking on pages with no sensitive actions, self-XSS, or issues requiring an already-compromised device or account.
Disclosure of publicly available information or version numbers.
How to report
Send reports to [email protected].
Please write in English and include as much of the following as you can:
A description of the vulnerability and its potential impact
The affected component, URL, endpoint, SDK, or version
Step-by-step instructions to reproduce the issue, including any proof-of-concept code or requests
Screenshots or recordings where helpful
Your name or handle and how you would like to be credited, if at all
You will receive an automated confirmation that your email was received. A human acknowledgement follows within the timeframe below.
What to expect from us
Stage	Target
Acknowledgement of your report	Within 3 business days
Initial assessment and severity rating	Within 10 business days
Status updates while the issue is open	At least every 30 days
Fix or mitigation for critical and high severity issues	As quickly as possible, typically within 30 days
Fix or mitigation for medium and low severity issues	Within 90 days, or bundled into a scheduled release
We will:
Confirm receipt and keep you informed of our progress
Work with you to understand and validate the issue
Notify you when the issue is resolved
Credit you publicly if you wish, once the issue is fixed
Some issues take longer to fix, for example when a change affects on-premise components or SDKs that customers must upgrade themselves. In those cases we will explain the delay and agree on a revised timeline with you.
Coordinated disclosure
We ask that you give us a reasonable opportunity to fix the issue before disclosing it publicly. Our default disclosure window is 90 days from the date we acknowledge your report, or the date a fix is released, whichever comes first.
If we need more time, we will tell you why and propose a new date. If you believe we are not acting in good faith, please tell us before publishing so we can address your concerns.
Please do not share details of an unfixed vulnerability with third parties, and do not include exploit details in public issue trackers, forums, or social media before the agreed disclosure date.
Research guidelines
To keep LicenseSpring and its customers safe while you test, please:
Use your own accounts and test data. A free trial account is sufficient for most testing against the Platform and License API.
Do not access, modify, or delete data that does not belong to you. If you encounter customer data, license keys, or personal information belonging to others, stop immediately and tell us in your report.
Do not attempt to pivot into internal systems or to persist access.
Do not run automated tools at a volume that could affect availability.
Do not attempt to extort or demand payment in exchange for withholding disclosure.
Safe harbour
LicenseSpring will not pursue legal action, or refer to law enforcement, security research conducted in accordance with this policy. We consider such research to be authorised, conducted in good faith, and exempt from restrictions in our Terms of Service that would otherwise prohibit it.
This safe harbour applies as long as you:
Follow the research guidelines above
Report the vulnerability promptly and only to [email protected]
Do not exploit the issue beyond what is needed to demonstrate it
Respect the coordinated disclosure timeline
If a third party takes legal action against you for research conducted under this policy, we will make it known that your activity was authorised.
Safe harbour does not extend to actions that violate the law, damage systems, or affect users other than yourself, nor to research against systems that LicenseSpring does not own or operate.
Recognition
LicenseSpring does not currently operate a paid bug bounty programme. With your permission, we will credit you by name or handle in our release notes or a public acknowledgements page once the issue is resolved.
Advisories and fixed issues
Security fixes for the Platform and License API are deployed by LicenseSpring and require no customer action. Fixes for SDKs, the Floating Server, and other distributed components are published as new releases and noted in the corresponding changelog.
Contact
Email: [email protected]
security.txt: https://licensespring.com/.well-known/security.txt
This policy was last updated on 16 September 2026 and is reviewed at least once a year.