Security Policy.
DXPR is committed to the security of our products and the data our customers entrust to us. This policy describes how we handle security vulnerabilities.
Responsible disclosure
We welcome reports from security researchers and the wider community. If you believe you have found a vulnerability in any DXPR product, please report it responsibly so we can investigate and address it before public disclosure.
Reporting a vulnerability
Send your report to security@dxpr.com. Include a description of the vulnerability, the steps to reproduce it, and the potential impact. If possible, provide a proof of concept. We accept reports in English and Dutch.
Response timeline
We aim to acknowledge receipt within two working days and to provide an initial assessment within five working days. Critical vulnerabilities are prioritized and may receive a faster response. We will keep you informed of our progress and coordinate disclosure timing with you.
Supported versions
Security fixes are provided for the current stable release of each DXPR product. Older versions that have reached end-of-life are not eligible for patches. We strongly recommend that all customers keep their installations up to date.
- DXPR Builder: current stable release on drupal.org
- DXPR Theme: current stable release on drupal.org
- DXPR CMS: current stable release on drupal.org
- DXPR Cloud (app.dxpr.com): always up to date
Security advisory format
When a vulnerability is confirmed and fixed, we publish a security advisory that includes a description of the issue, the affected versions, the severity rating (using the Drupal security advisory rating system), and the recommended upgrade path. Advisories are published on drupal.org/security and on the DXPR blog.
Scope
This policy applies to DXPR Builder, DXPR Theme, DXPR CMS, and the DXPR Cloud platform. Third-party integrations and Drupal core vulnerabilities fall under their respective maintainers' policies. If you are unsure whether an issue is in scope, report it and we will determine the responsible party.
Safe harbor
We will not pursue legal action against researchers who follow this policy and act in good faith. We ask that you do not access or modify other users' data, disrupt our services, or disclose findings publicly before we have had a reasonable opportunity to address them.