247-IT Security
Security
How to report a security vulnerability to us and how security updates reach you.
Report a vulnerability
Contact
Please report security vulnerabilities by e-mail to
and start the subject with SECURITY. It helps to include the affected version,
a short description and the steps to reproduce the issue.
Please do not publish details (forums, social media, public issues) while no fix is available yet.
Response times
- Acknowledgement within 3 business days
- Initial assessment within 10 business days
We agree on a reasonable period with you before any details are made public.
Scope
This policy covers the UPS Hyper-V Shutdown Monitor itself: desktop app, Windows service, remote web interface, updater and installer.
Attacks on Hyper-V hosts, UPS devices or other third-party infrastructure are out of scope. Please test only against your own isolated test installation — the software can shut down real servers.
Safe harbor
Research and reports made in good faith and in a proportionate way under this policy will not lead to legal action by 247-IT.
Security updates
Delivery
Security updates are free of charge. The desktop app announces new versions and installs them on request; the remote web interface shows available updates on its About page. Before installing, the updater verifies the setup file against its SHA-256 checksum.
Labelling
Updates that fix a security vulnerability are labelled security update in the release notes — in the app and on the What's new page. Please install them promptly.