Found something?Tell us.

A control plane for a fleet of laptops is worth attacking. We would rather hear about a hole from you than from whoever finds it next.

Last updated: August 2026

How to report

Email security@bb-open.com with enough detail to reproduce the issue: the version, the steps, and what you were able to reach. That is the address SECURITY.md in the repository names, and it reaches the steward rather than the issue tracker. If you would rather encrypt it, ask for a key first.

What happens next

You get a human reply within three working days. We confirm or reject the finding within ten, and if we confirm it we tell you when a fix is planned. You hear when it ships, and you are credited by name in the advisory unless you would rather not be.

What we ask

Give us reasonable time to fix it before it becomes public. Do not run denial-of-service tests, do not access data that is not yours, and do not change or delete anything. Stay inside your own installation or ask us for a test environment.

What we promise in return

If you report in good faith and stay inside those lines, we will not take legal action against you. We have no bug bounty; what we have is credit, a fast reply and a fix.

Where advisories appear

In the repository on Codeberg, in the release notes, and by email to organisations with a support agreement. Fixes for supported releases are backported.

These pages cover this website. The steward runs it and is responsible for what happens on it; the software itself is governed by its licence. Need them in Dutch, or a signed copy? Ask.