LicenseSpring

Vulnerability Disclosure Policy

Last updated: September 16, 2026

LicenseSpring takes the security of its platform, APIs, SDKs, and tooling seriously. We value the work of security researchers and welcome reports of vulnerabilities in our products and services. This page describes what is in scope, how to report a finding, what you can expect from us, and the protections we offer to researchers who act in good faith.

This policy is LicenseSpring's coordinated vulnerability disclosure (CVD) policy and serves as our single point of contact for vulnerability reports under the EU Cyber Resilience Act (Regulation (EU) 2024/2847).

Scope

In scope

The following LicenseSpring-operated systems and software are in scope:

If you are unsure whether something is in scope, report it anyway. We would rather receive a report we cannot act on than miss a real issue.

Out of scope

The following are not eligible under this policy:

How to report

Send reports to security@licensespring.com.

Please write in English and include as much of the following as you can:

You will receive an automated confirmation that your email was received. A human acknowledgement follows within the timeframe below.

What to expect from us

StageTarget
Acknowledgement of your reportWithin 3 business days
Initial assessment and severity ratingWithin 10 business days
Status updates while the issue is openAt least every 30 days
Fix or mitigation for critical and high severity issuesAs quickly as possible, typically within 30 days
Fix or mitigation for medium and low severity issuesWithin 90 days, or bundled into a scheduled release

We will:

Some issues take longer to fix, for example when a change affects on-premise components or SDKs that customers must upgrade themselves. In those cases we will explain the delay and agree on a revised timeline with you.

Coordinated disclosure

We ask that you give us a reasonable opportunity to fix the issue before disclosing it publicly. Our default disclosure window is 90 days from the date we acknowledge your report, or the date a fix is released, whichever comes first.

If we need more time, we will tell you why and propose a new date. If you believe we are not acting in good faith, please tell us before publishing so we can address your concerns.

Please do not share details of an unfixed vulnerability with third parties, and do not include exploit details in public issue trackers, forums, or social media before the agreed disclosure date.

Research guidelines

To keep LicenseSpring and its customers safe while you test, please:

Safe harbour

LicenseSpring will not pursue legal action, or refer to law enforcement, security research conducted in accordance with this policy. We consider such research to be authorised, conducted in good faith, and exempt from restrictions in our Terms of Service that would otherwise prohibit it.

This safe harbour applies as long as you:

If a third party takes legal action against you for research conducted under this policy, we will make it known that your activity was authorised.

Safe harbour does not extend to actions that violate the law, damage systems, or affect users other than yourself, nor to research against systems that LicenseSpring does not own or operate.

Recognition

LicenseSpring does not currently operate a paid bug bounty programme. With your permission, we will credit you by name or handle in our release notes or a public acknowledgements page once the issue is resolved.

Advisories and fixed issues

Security fixes for the Platform and License API are deployed by LicenseSpring and require no customer action. Fixes for SDKs, the Floating Server, and other distributed components are published as new releases and noted in the corresponding changelog.

Contact

This policy was last updated on 16 September 2026 and is reviewed at least once a year.