Trust center
Vulnerability disclosure
How to report a security issue, what to expect, and where advisories are published.
Report security issues privately to the security address below. Please do not open a public issue.
How to report
- Email: security@segaudit.com. The same address and policy are in /.well-known/security.txt.
- Include the version, steps to reproduce, and impact. Use the built-in Northline Process sample so no customer data is needed.
What to expect
| Step | Target |
|---|---|
| Acknowledge your report | 2 business days |
| Initial assessment | 5 business days |
| Fix or mitigation for High and Critical issues | 30 days |
| Public advisory | When a fix is available, credited to you if you wish |
Safe harbor
We will not pursue legal action against good-faith research that avoids privacy violations and service disruption, and that gives us reasonable time to fix the issue before disclosure.
Advisories
Security advisories are published on the security advisories page, with the affected versions, fixed version and workaround, and in its Atom feed. Security fixes ship in fix releases, which every edition may install whatever its license says. The updates page tells you whether your version is affected.
Last updated 2026-10-04.