Security & compliance
Upholding the highest standards to protect your data and ensure trust.

Reporting a security issue
Devolutions Inc. is dedicated to performing exceptional due diligence when developing and delivering solutions, in order to prevent and mitigate threats that may have a negative impact upon our customers' data, and upon our ability to provide safe, reliable, and compliant products and services. To achieve this critical objective, we employ industry-leading frameworks, standards, controls, processes, and best practices, including our private Bug Bounty Program.
About the program
Transparency is a core fundamental value at Devolutions, as it fosters
healthy relationships, establishes trust, and promotes a culture of
openness, improvement and innovation. Our bug bounty program, which is
hosted on YesWeHack.com, encourages researchers to try to “attack and break”
our products, so that we can proactively fortify vulnerabilities and fix
coding/programming errors.
Please note enrollment in our bug bounty
program is currently by invitation only via
YesWeHack.com.
To request an
invitation, email your YesWeHack username to
security@devolutions.net.
Responsible disclosure
We continuously encourage researchers and customers to report identified vulnerabilities. To better protect our customers, reports remain confidential until vulnerabilities have been confirmed, resolved and released into production by Devolutions. We strive to do our best to address vulnerabilities within a reasonable and industry-acceptable timeframe.
Bug bounty scope
The following products and services are in the scope of our bug bounty program:
-
Devolutions Server
-
Remote Desktop Manager (Windows)
-
Devolutions Gateway
-
Devolutions Cloud
-
Devolutions Send
-
Devolutions Portal and Devolutions Account
-
Devolutions Crypto
-
The devolutions.net website and blog
The full scope, rules and exclusions are listed on the program page on YesWeHack.
Reporting a security issue
While we do take care of the security of our products, the fast-changing nature and complexity of security may inadvertently expose our software or supporting infrastructure to vulnerabilities. If you identify such a vulnerability, please send us your report in a timely manner. Vulnerabilities in the scope of our bug bounty program must be reported through our YesWeHack program; we do not accept them by email. For issues outside the program's scope, email us at security@devolutions.net. The report should include the following items:
-
A clear description of the vulnerability, how it can be exploited, and its security impact on the application, its users and Devolutions.
-
Complete steps to reproduce, including code snippets, payloads or commands when needed.
-
Proof of exploitation, such as screenshots showing the exploit and its final impact.
-
Remediation advice, if possible and applicable.
Once submitted, allow us a reasonable time frame to provide some feedback. Our security team must:
-
Reproduce and confirm the vulnerability as described in your report.
-
Establish a severity score according to CVSS 3.1.
-
Consider the recommendations from your report and build an action plan with relevant teams.
-
Maintain communication with the reporter until the case is resolved.
We kindly ask to maintain the report and its content confidential until the appropriate corrective measures are released in production. Please also note that exploiting a reported vulnerability abusively or for illegal, malicious or other inappropriate purposes may result in legal prosecutions against the reporter, which could lead to civil or criminal liability. An action is considered abusive or inappropriate when its purpose compromises customer-related or internal confidential information in an undue or disproportionate manner, or when such an action has some other aim than the demonstration of a vulnerability.

Rewards
Researchers are rewarded for reported vulnerabilities* in three important ways:
Once a vulnerability is fixed and a patch is released to production, researchers can publicize their discovery and contribution on their blog/social media pages. Doing this elevates their profile and standing in the IT & IT security communities and may support career advancement goals. On request, we also credit researchers who report valid vulnerabilities in our security advisories.
We offer financial rewards** based on the CVSS 3.1 severity and the actual business impact of each reported vulnerability. For critical issues, researchers can earn up to $5,000.00 per issue (USD).
From time to time, we may also provide participating researchers with Devolutions-branded merchandise.
*A vulnerability is a hole or a weakness in the application, which can be a design flaw or an implementation bug, that allows an attacker to cause harm to the stakeholders of an application. Stakeholders include the application owner, application users and other entities that rely on the application.
**Payout amounts vary according to the quantity of vulnerabilities or affected components, as well as the overall quality of the report. Only the first reporter of a qualifying vulnerability is eligible for a financial reward. Current and former employees of Devolutions and its contractors are not eligible.
How to enroll
At this time, enrollment in our bug bounty program is by invitation only.
We hand out invitations to security researchers and customers at various
events throughout the year (e.g. Hackfest, NorthSec, etc.). You can also
request an invitation at any time: create an account on
YesWeHack.com, then email your YesWeHack
username to security@devolutions.net and
we will invite you to the program.
By registering for our bug bounty
program, you authorize us to communicate with you by email to respond to your
submissions, requests and inquiries, and for other purposes related to the
management of the program or your participation in the program in general.
