Security

Embedthis takes the security of its software seriously. Our products are often deployed on devices that remain in service for many years and may be difficult to update. Security is therefore built into our products from the outset and maintained throughout their supported lifecycle.

Reporting a Vulnerability

If you believe you have discovered a security vulnerability in an Embedthis product, please report it to security@embedthis.com.

Please include:

We will acknowledge your report promptly and keep you informed as we investigate, develop a resolution, and coordinate disclosure.

Responsible Disclosure

We appreciate responsible security research and ask that you allow sufficient time for the issue to be resolved before making it public.

Embedded products can take considerably longer to update than conventional enterprise software. A fix must often be incorporated, tested, and distributed by multiple device manufacturers before it reaches deployed devices. For this reason, we coordinate public disclosure so that a security update is available and affected manufacturers have had a reasonable opportunity to update their products.

Following this coordination period, we publish vulnerability details, including the affected versions, security impact, and available remediation.

Security Notifications

Customers are notified of security issues and updates through the Embedthis Builder. You can subscribe to security notifications in the Builder to receive advisories and remediation information before public disclosure.