---
title: Coordinated Vulnerability Disclosure Policy
description: How to report a security vulnerability in a Blues product, what Blues commits to in return, and how Blues coordinates disclosure, publishes advisories, and distributes security updates.
source_url: https://dev.blues.io/security-advisories/disclosure-policy/
canonical_url: https://dev.blues.io/security-advisories/disclosure-policy/
markdown_url: https://dev.blues.io/security-advisories/disclosure-policy.md
---

# Coordinated Vulnerability Disclosure Policy

Blues welcomes reports of security vulnerabilities in its products and coordinates their disclosure with the people who report them.

This policy explains how to report a vulnerability, what to expect from Blues in return, and how Blues publishes advisories and distributes security updates.

## Reporting a vulnerability

Report vulnerabilities to [**security@blues.com**](mailto:security@blues.com). This is the only reporting channel Blues offers. No support contract, Notehub account or commercial relationship is required — reports are accepted from anyone.

The policy applies to the Blues products with digital elements: the **Notecard** (Cellular, Cell+WiFi, WiFi, LoRa and Skylo variants), **Starnote** (Skylo and Iridium satellite accessories), and **Notehub**. Vulnerabilities in a host product that integrates a Notecard, in an integrator’s own cloud, or in an integrator’s use of the Notecard API are for that manufacturer to address; Blues supports the disclosure where a Blues component is implicated.

The [Security Advisories](https://dev.blues.io/security-advisories.md) page is where you will find the reporting address, this policy, and the archive of published advisories.

## What you can expect from Blues

Blues acknowledges your report, naming the team member handling it and a reference for the case. You will receive an initial assessment covering whether the vulnerability has been reproduced, which products and versions are affected, an assigned severity, and the expected remediation timing.

Reporters are kept updated through investigation and remediation, and are told when the fix is released and when the advisory is published. If you wish to be named, you are credited in the advisory once the fix is released.

An incomplete report is still accepted and assessed — Blues will ask for the missing details rather than close the case.

## Safe harbor

Where a reporter acts in good faith and within the law, Blues treats their research as authorized and will not pursue or support legal action against them — including claims under computer-misuse or anti-circumvention law — provided they:

- report privately through security\@blues.com;
- give Blues a reasonable opportunity to remediate before disclosing publicly;
- access only what is needed to identify and demonstrate the vulnerability, without accessing another user’s data; and
- do not disrupt the service.

This authorization covers only Blues’ own products and systems. It does not authorize access to, or waive the rights of, any third party — including customers whose products contain a Notecard and the owners of Notehub projects. If you are unsure whether an action is covered, ask at <security@blues.com> before proceeding.

## Coordinated disclosure

Blues publishes an advisory once a security update is available; the ordinary case is that Blues publishes when users are in a position to act. Where remediation will take materially longer, Blues will agree an extended date with the reporter, or publish an advisory describing a workaround without waiting for the fix.

Where a vulnerability is confirmed to be actively exploited, Blues may publish before a fix is available: withholding information about a vulnerability attackers are already using leaves users unable to defend themselves.

Blues honors embargo dates agreed with a reporter, an upstream maintainer or a coordinating CSIRT, and asks the same in return. Where a coordinator is already handling a case affecting several vendors, Blues aligns to its date rather than publishing unilaterally. Blues does not fix silently and decline to publish.

## Advisories

Advisories are published to the archive on the [Security Advisories](https://dev.blues.io/security-advisories.md) page, which is the authoritative record, and are referenced from the firmware release notes for the release carrying the fix. Where a Notehub vulnerability had service impact, the advisory is also posted to the Blues status page at [status.notehub.io](https://status.notehub.io).

Each advisory states:

- **The vulnerability** — the nature of the flaw and the preconditions for exploiting it, in enough detail for you to judge whether your deployment is exposed.
- **The affected product** — the affected firmware line and version range, or the affected Notehub component and the dates the service was affected.
- **Impact and severity** — an impact statement in plain terms, a CVSS base score and vector, and an assigned severity.
- **Remediation** — the version carrying the fix, how to obtain and apply it, any workaround for users who cannot update immediately, and how to verify the installed version.
- **Identifiers** — the Blues advisory identifier, any CVE, the publication date, and a revision history where the advisory is updated after publication.

An advisory remains published for as long as the update it describes remains available; it is not withdrawn because the affected version is old. Blues withholds working exploit code until users have had a reasonable opportunity to update — for longer on the lines that cannot be updated over the air.

## Security updates

Security updates are disseminated without delay once released, and free of charge. Every long-term-support (LTS) release carries ten years of free security updates and bug fixes from its release date, uniform across the firmware lines and available to every SKU. No support contract, subscription, paid tier or Enterprise Agreement is required.

Each security update is accompanied by release notes referencing the advisory and any CVE, by the advisory itself, and by a notification to the owners of affected Notehub projects — stating which line and versions are affected, which version carries the fix, how to obtain it, and what to do in the meantime if you cannot update immediately.

Updates are distributed through Notehub. The update path differs by product line: over the air for the Cellular and WiFi Notecards; via the paired Notecard for Starnote; and by a local wired (USB) connection for Notecard for LoRa, which has no over-the-air path.

***

This is the public version of Blues Inc.’s Coordinated Vulnerability Disclosure Policy, kept in step with the full policy maintained internally. For the reporting address and the current advisory archive, see the [Security Advisories](https://dev.blues.io/security-advisories.md) page.
