Security at Evertrust

Evertrust welcomes reports of security vulnerabilities affecting our products and services. This page explains how to reach our security team and how we handle reports.

Report a vulnerability

Email csirt@evertrust.fr. Reports in English or French are welcome. Please use this address for vulnerabilities; for routine product support, use Evertrust Support.

If your report contains an exploit, sensitive technical details, or customer information, encrypt the message and attachments with our CSIRT OpenPGP public key. Keep the subject line nonsensitive: OpenPGP email encryption does not protect mail headers or metadata.

Verify our OpenPGP key

  • User ID: Evertrust CSIRT <csirt@evertrust.fr>

  • Primary-key fingerprint: 00C2 634A 9C25 79AA D917 92AC 1FE1 9D44 E6CC 102B

  • Algorithm: RSA-4096 (including the encryption subkey)

  • Key expiration: 24 September 2028

  • Public-key file: pgp-key.asc

Compare the fingerprint shown by your OpenPGP client with the one above before encrypting. The public key is also linked from security.txt.

To help us investigate, include the affected product and version, deployment context, a concise impact assessment, reproducible steps or a minimal proof of concept, and any known mitigations. Tell us how to contact you and whether you consent to public acknowledgement. Do not include unrelated personal or customer data.

What is in scope

We accept reports concerning currently supported Evertrust products, including Stream and Horizon, and Evertrust-operated services such as evertrust.io and docs.evertrust.fr. Security issues in third-party components as integrated into an Evertrust product are also in scope: please tell us which product and version is affected, even if the underlying defect originates upstream.

For supported versions and last dates of support, consult the product lifecycle pages. We will still review reports about older releases to understand their impact, but a fix for an unsupported release is not guaranteed. Reports about an unrelated third-party product should go to its vendor.

Research guidelines

Only test systems you own or are expressly authorized to assess. Limit testing to what is needed to demonstrate the issue, and stop if you encounter data that is not yours. Do not exfiltrate, alter, or destroy data; disrupt availability; conduct denial-of-service tests; or use social engineering or physical intrusion. If you inadvertently encounter sensitive data, stop, preserve only the minimum evidence needed, and contact us promptly through the encrypted channel above.

These guidelines describe how to submit a report; they do not grant permission to test Evertrust or customer systems without authorization.

How we handle reports

We acknowledge and triage incoming reports, investigate affected products and versions, assess severity and exploitability, and coordinate remediation with the relevant teams and suppliers. We keep the reporter informed as the case progresses where contact details are available. We may coordinate with relevant authorities or CERTs, including CERT-FR, when appropriate.

Please give us a reasonable opportunity to investigate and prepare mitigations before publishing technical details. We coordinate disclosure timing with reporters and affected parties case by case, considering user risk, available fixes, and any legal reporting obligations. We do not publish a fixed response-time commitment or disclosure deadline on this page.

When a public advisory is warranted, we aim to describe affected versions, impact, mitigations, and available updates. We will acknowledge researchers who request it and whose contribution can safely be disclosed. We do not publish a reporter’s identity without their consent.