DFIRe Vulnerability Disclosure Policy ===================================== Security contact: antti@dfire.fi Canonical URL: https://dfire.fi/security_policy.txt Last updated: 2026-08-13 DFIRe is case management software for digital forensics and incident response. The people who use it keep evidence and investigation records in it, so a defect in DFIRe can expose material that matters. We want to hear about security problems, and we would rather hear about them from you than from a customer. Reporting a vulnerability ------------------------- Send the report to antti@dfire.fi, in English or Finnish. Include as much of this as you have: - What the problem is, and what an attacker gets from it. - The DFIRe version you tested, or the host name if you tested a site of ours. - Steps to reproduce. A request and response transcript, a short script, or a screen recording all work. - Anything you already know about a fix. Do not put case data, customer data, or personal data in the report. If you found a way to read data that is not yours, describe the access. Do not send us the contents. What happens next ----------------- - We acknowledge your report within 5 business days. - Within 10 business days we tell you whether we accept it as a vulnerability and how severe we consider it. - After that we give you a fix timeline and keep you informed as it moves. - We tell you when the fix ships and in which version. If a reply is late, send a reminder to the same address. Scope ----- In scope: - The DFIRe application, tested on an installation you run yourself. A free license for research is available at https://dfire.fi/free-license.html - https://dfire.fi - https://license.dfire.fi Out of scope: - Installations run by DFIRe customers. Those are other organizations' systems, on their networks, holding live investigation data. Testing one needs that organization's written permission, which we cannot give on their behalf. - The public demo instance. - Services DFIRe integrates with, such as Slack, Jira, and the enrichment providers. Report those to the service itself. - Findings that need physical access to a server, an already compromised administrator account, or a modified DFIRe build. - Scanner output with no working proof of concept. - Missing hardening headers and TLS configuration preferences, unless you can show an attack they enable. Rules for testing ----------------- Follow these and the safe harbor below applies: - Test on your own installation wherever the finding allows it. - Do not read, change, or delete data that is not yours. If a proof of concept needs data, use records you created. - Stop once you have confirmed the problem. Do not go further into a system than the finding requires. - No denial of service, no load testing, no password guessing at scale, no spam. - No social engineering and no physical intrusion, against us, our customers, or our suppliers. - Keep the finding confidential until the disclosure date below. Ask first if you are not sure that this policy covers what you plan to do. Safe harbor ----------- Follow this policy in good faith and we will not report you to law enforcement and will not bring a civil claim against you over the research. We will confirm that in writing if a third party asks. The DFIRe license agreement forbids reverse engineering. For research under this policy, on an installation you run yourself, we waive that restriction as far as the research needs it. Every other term of the license stands. This is a commitment by DFIRe Oy about DFIRe Oy's own software and systems. It cannot bind a customer whose installation you tested, which is why customer installations are out of scope. Disclosure ---------- You may publish 90 days after we acknowledge your report, whether or not a fix has shipped by then. If you need longer, or want to publish earlier because the issue is already public or under attack, tell us and we will agree on a date. Fixed security issues appear in the changelog at https://dfire.fi/docs/changelog.html. We credit the reporter by name unless you ask us not to. Tell us the name you want. There is no bounty program. We do not pay for reports. Everything else --------------- For bugs that are not security problems, and for feature requests and support, write to contact@dfire.fi instead.