Security Advisories
Notices about security issues affecting Blues products. For live service incidents, see Notehub Status.
No advisories published
There are no current security advisories for Blues products.
Resources
Security, Reliability, and Governance
A comprehensive overview of Blues' security and resiliency programs, from hardware-level security to operational policies.
Coordinated Vulnerability Disclosure Policy
How to report a vulnerability, what Blues commits to in return, and how advisories and security updates are published.
Firmware Release Policies
How Blues versions, supports, and patches Notecard and Starnote firmware, including the 10-year security-fix commitment for LTS releases.
Notehub Status
Live operational status and incident history for the Notehub service.
Report a potential vulnerability
Found a potential security issue in a Blues product? Please send us the details using the guidelines provided below. The full Coordinated Vulnerability Disclosure Policy sets out what to expect in return, including safe harbor for good-faith research.
Email security@blues.comWhat to include
- The affected product and firmware version.
- A description of the issue and steps to reproduce it.
- Please do not include credentials, personal data, or customer data unless it is essential to demonstrating the issue.
What happens next
- We will investigate, keep you informed, and coordinate any disclosure with you before publishing an advisory.
- Blues will not pursue legal action against researchers who report in good faith and avoid privacy violations, data destruction, and service disruption.