Security

Report a security issue

CIQ accepts reports of security issues at the security@ciq.com email address. CIQ provides a public GPG key so the reporter can protect sensitive aspects of a report.
Key fingerprint
9450 B113 AC94 3355 90BE E5C5 3AE5 0DAD 302F 2BC0
Response time
Email sent to security@ciq.com is read and acknowledged with a non-automated response within two business days.

How CIQ handles a report

CIQ engages with partners, vendors, researchers, and community coordinators to disclose newly discovered vulnerabilities in a timely manner, taking into account the complexity and severity of the issue and any coordinated disclosure agreements with stakeholders.

Issues under embargo

CIQ does not disclose, discuss, or confirm the issue until an investigation is conducted and a fix is available.

After an embargo lifts

CIQ publishes details of the flaw, including a CVE identifier where applicable and the CIQ products or services affected.

Machine-readable contact details are published at /.well-known/security.txt.