This page provides guidance on how to report a security vulnerability identified within the MachineWorks or Polygonica software libraries.
This vulnerability disclosure policy applies to any vulnerabilities you are considering reporting to MachineWorks. We recommend you read this policy in full before submitting any reports to us, and always act in compliance with it.
MachineWorks take cybersecurity issues seriously and value reports of security vulnerabilities. However, we do not offer monetary rewards for vulnerability disclosures.
If you believe you have found a security vulnerability, please submit your report to us using the MachineWorksor Polygonica technical support portal. Please include the keyword 'Cybersecurity' in the title of the ticket; doing so will allow us to flag the report for high-priority investigation.
In your report, please include details of:
After a real security vulnerability has been reported we will acknowledge receipt within 3 working days. Weaim to triage your report and respond to you within ten working days.
Priority for remediation is assessed by looking at the impact, severity and exploit complexity. Vulnerability reports might take some time to triage or address. We'll also aim to keep you informed of our progress. You are welcome to enquire on the status, but should avoid doing so more than once every 14 days. This allows our teams to focus on the remediation. We will notify you when the report vulnerability is remediated, and you may be invited to confirm that the solution covers the vulnerability adequately.
We aim to provide software patches containing a resolution for the problem with 90 days but may require extensions for complex problems.
You must not:
MachineWorks will not pursue legal action against researchers who:
This safe harbour covers activities that might otherwise violate:
