RootTrace

RootTrace Security Policy

RootTrace is developed by ByteAffinity. This is our coordinated vulnerability disclosure policy. It covers the RootTrace platform: the backend, the frontend, the diagnostics collector, and the published SDKs. Test, demo, and third-party-hosted environments that ByteAffinity does not operate are out of scope, though we are still glad to hear about them.

Report vulnerabilities privately to security@roottrace.io. Do not open a public GitHub issue for a security report. A PGP key for encrypted reports is available from the same address; use it for anything containing exploit details, customer data, or credentials.

A useful report names the affected version or build, the deployment mode (cloud or on-prem), the impact, and how to reproduce it.

What happens next

We acknowledge reports and triage them in severity order, judged on CVSS base score adjusted for RootTrace's read-only, outbound-only posture and its tenant isolation model. Critical and actively exploited issues are worked ahead of other engineering. We keep the reporter informed and credit reporters who want to be named once a fix is available.

We ask for a reasonable opportunity to remediate before public disclosure, and we will agree a timeline with the reporter. Fixes ship in the current build; on-prem and OEM deployments pick them up by upgrading, per the upgrade guide.

Safe harbor

We will not pursue legal action against researchers who follow this policy in good faith: who avoid privacy violations, data destruction, and service degradation, who interact only with accounts they own or have permission to test, and who give us time to remediate before disclosing. Testing against another customer's tenant or data is never in scope.

Embedded and white-label deployments

RootTrace can be deployed white-labeled inside a larger product, as described in the OEM integration guide. If you ship it that way, you are the vendor your end customers report to, and handling their reports and their remediation timing is yours to run. Where a report turns out to be a RootTrace issue, send it to security@roottrace.io and we will handle it under this policy.

A Software Bill of Materials and a description of the handling above, for your own component due diligence (including under the EU Cyber Resilience Act), are available on request. Nothing here is a legal determination of any party's obligations, which depend on your product and on how RootTrace is integrated into it.

Status of this policy

This policy describes how we intend to work with reporters and partners. It is a statement of practice, not a warranty, a service level agreement, or a contract, and no timing or outcome described here is guaranteed. Where a customer, support, or partner agreement covers the same ground, that agreement governs. We may update this policy at any time.