Security

Security & Coordinated Vulnerability Disclosure

The security of DataGerry and the protection of our users are a top priority for us.
We are continuously improving DataGerry and regularly review the security of our software and its dependencies. If you discover a security vulnerability in DataGerry, we would appreciate a responsible and coordinated report.

Report a Security Vulnerability

If you have discovered a potential security vulnerability in DataGerry, please contact us at:

security@datagerry.com

Please use this address exclusively for reports of potential security vulnerabilities and security-related issues.

Please do not report security vulnerabilities via public GitHub Issues, community forums, or other public channels. This allows us to investigate the report first and, if necessary, provide a security update.

What information should a report include?

To help us investigate and evaluate a report as quickly as possible, we ask that you provide the following information, if possible:

• Affected DataGerry version
• Affected component or feature
• Description of the security vulnerability
• Steps to reproduce the issue
• Expected and actual behavior
• Potential impact of the security vulnerability
• Proof of Concept (PoC), if available
• Relevant logs, screenshots, or other technical information
• CVE, CWE, or other references, if available
• Contact information for follow-up questions

The more technical information you can provide, the easier it will be for us to understand and evaluate your report.

How We Handle Security Alerts

Once we receive a report, we review and evaluate it.
Our process generally consists of the following steps:

1. Receipt of the report
2. Technical review and reproduction
3. Assessment of the impact and risk
4. Identification of affected versions and components
5. Development and testing of a fix or risk mitigation measure
6. Release of a security update
7. Publication of relevant security information

For confirmed security vulnerabilities, we take into account, in particular, the severity of the vulnerability, the affected versions, the potential impact, and the availability of measures to resolve or mitigate the risk.

Coordinated Disclosure

We ask security researchers and others who discover security vulnerabilities to first give us the opportunity to investigate the report and take appropriate action.

We aim for coordinated disclosure, in which technical details are published in a way that, whenever possible, allows users sufficient time to apply available security updates or implement other protective measures.

Please do not publicly disclose detailed information or proof-of-concept code regarding an unpatched vulnerability before coordinating the next steps with us.

Handling Reports

We treat incoming security reports confidentially and use the information provided solely for the investigation, assessment, and resolution of the reported security issue, as well as for related security and compliance processes.

We also ask reporters not to send us any personal data, login credentials, or other confidential information that is not necessary for the analysis.

Supported Versions

Information about currently supported DataGerry versions and their security support is published on the DataGerry website or in the respective release and product information.

Security updates are provided for supported versions to the extent that this is necessary and technically feasible for the respective version and the security issue in question.

Safety Information

Information regarding resolved and disclosed security vulnerabilities will be published through our official DataGerry channels, provided that public disclosure is possible and appropriate.
A published security advisory includes, where available and appropriate:

• Affected DataGerry versions
• Fixed versions
• Description of the vulnerability
• Severity and impact
• A CVE reference, if applicable
• Information on the fix
• Required actions for users

Contact

Security Contact:
security@datagerry.com

Please use this contact information exclusively for security-related reports.
For general questions, support requests, or product inquiries, please use the designated DataGerry channels.

Are you ready to take control of your data?

Start your 14-day free trial of DataGerry today.

Try DataGerry, the open-source CMDB that brings structure and flexibility to your IT documentation. Discover powerful features, automate your workflows, and gain a complete overview of your assets—with no obligations.