Security & responsible disclosure

We build infrastructure that sits in the path of every connection our customers make. Tell us when we get it wrong, and we will treat it accordingly.

Last updated: 13 August 2026

Reporting

Use the contact form and choose “security disclosure”, with enough detail to reproduce: affected component and version, the steps, and the impact you believe it has. If you need an encrypted channel for the details, say so in the message and we will set one up before you send anything sensitive.

Please do not open a public GitHub issue for a security defect. The repository is public, so an issue is a disclosure.

What we commit to

We acknowledge a report within two business days and give you an initial assessment within five. We will keep you updated as we work, tell you when a fix ships, and credit you in the release notes unless you would rather we did not.

We will not pursue legal action against anyone acting in good faith under this policy. We do not currently run a paid bounty — if that changes it will say so here.

Scope

In scope: the SpatiumDDI platform, the appliance images, and the spatiumnorth.com website (spatiumddi.com redirects here).

Out of scope: findings in third-party services we merely use, reports generated by an automated scanner with no demonstrated impact, and anything requiring physical access or social engineering of our people.

Good-faith rules

Test only against your own installation. Do not access, modify or exfiltrate anyone else’s data, do not degrade a production service, and give us a reasonable window to fix an issue before disclosing it publicly. Ninety days is our default, and we will usually be much faster.

Write to us through the contact form →