MultiPortal builds software that other organisations install and run on their own infrastructure. Security researchers, customers and members of the public sometimes find security weaknesses in that software or in the services we operate. This policy explains how to report a weakness to us safely, what we will do with your report, and what you can expect back.
Scope
This policy covers security weaknesses in:
- all MultiPortal products and the code we publish for customers to install, both those available now (currently MultiPortal Core and MultiPortal Migrator) and any products we release in future;
- the services MultiPortal operates directly, such as the website, the demo environment, the community forum and the wiki;
- the systems and infrastructure we host to run those services.
It does not cover systems that customers run themselves once they have installed our software, or third-party services we do not control. If your report concerns a customer's own deployment, we will help you reach the right party where we reasonably can, but we cannot act on someone else's infrastructure.
Our commitment to you (safe harbour)
MultiPortal will not pursue or support legal action against anyone who, in good faith and in line with this policy:
- makes a genuine effort to avoid harming people, data and the availability of services while investigating;
- only accesses the minimum amount of data needed to demonstrate the weakness, and does not access, change or delete anyone else's data;
- does not use the weakness beyond what is needed to confirm it exists;
- gives us a reasonable chance to fix the problem before telling anyone else; and
- does not extort, threaten, or demand payment in exchange for the report.
If you act in good faith under this policy, we will treat your actions as authorised, work with you to resolve the issue quickly, and will not report you to the authorities for that research. If you are unsure whether something is allowed, ask us first. This safe harbour applies only to MultiPortal's own products and services; it cannot authorise testing against systems owned by our customers or third parties.
Please do not
- run denial-of-service, spam, or automated high-volume tests against our services;
- access, download, modify or delete data that is not yours;
- use social engineering, phishing, or physical intrusion against our staff or offices;
- publish or share the weakness before we have had a reasonable chance to fix it; or
- demand payment as a condition of telling us.
How to report
Email security@multiportal.io. For anything sensitive, please encrypt your report with our OpenPGP key.
- Public key: /.well-known/security-pgp-key.asc (also discoverable by email address via Web Key Directory, and listed in our security.txt).
- Key fingerprint:
8637 3AE5 F160 F86C 8700 5967 6145 2D62 2AF6 1777
Please include, as far as you can: what the weakness is and which product, version or service it affects; how to reproduce it or a proof of concept; what an attacker could do with it; and how we can reach you, including whether you would like to be credited. We accept reports in English.
What you can expect from us
- Acknowledgement that we have received your report, within 5 business days.
- Triage, where we assess the report and set a severity, within 10 business days.
- Updates on progress at least every two to three weeks while the issue is open.
- Resolution prioritised by severity, and notice when it is fixed.
Because customers install and run MultiPortal themselves, a product fix only protects them once they upgrade, so we may coordinate timing with a release and, for serious issues, a customer notification.
Coordinated disclosure
We follow coordinated disclosure and ask that you give us a reasonable time to fix an issue before making it public. As a guide we aim to be ready for disclosure within 90 days of triage, and we will tell you if something needs longer and why. We are happy to agree a timeline with you, to credit you for the finding if you would like, and to coordinate a joint advisory where that helps customers.
Recognition
MultiPortal does not currently run a paid bug bounty. We value the work researchers do and, with your permission, will publicly acknowledge your contribution.
Last updated: July 2026.