| Version | Supported |
|---|---|
| 1.x (latest minor) | Yes |
| < 1.0 | No |
Do not open a public GitHub issue for security vulnerabilities.
Use GitHub Security Advisories to report vulnerabilities privately:
- Go to the Security tab of this repository
- Click "Report a vulnerability"
- Fill in the vulnerability details
If GitHub Security Advisories are unavailable to you for any reason, email developer@exabeam.com with the subject line observra security report and the same level of detail.
- Data confidentiality: telemetry data exfiltration, credential leakage through event capture
- Data integrity: event tampering, injection of false telemetry events
- PII exposure: failure of the redaction engine to mask sensitive data
- Acknowledgement: within 48 hours
- Initial assessment: within 7 days
- Fix development: critical (days), high (weeks), medium (next minor release)