Last Updated: 30-Jun-2026
Farsight Tech Nordic builds ProVide with security as a foundation, not an afterthought. This page explains how to report a security issue, what you can expect from us in return, and how we handle security updates and advisories. It is the policy referenced by our security.txt.
If you believe you’ve found a security vulnerability in ProVide or on our website, please tell us privately at security@provideserver.com. We accept reports in English or Swedish.
To help us assess and reproduce the issue quickly, please include where you can:
If you need to share sensitive details, contact us first and we’ll arrange a secure channel. Please give us a reasonable opportunity to investigate and release a fix before disclosing the issue publicly. We’re committed to working with you on coordinated disclosure.
We do not currently operate a paid bug-bounty program.
We will not pursue or support legal action against researchers who act in good faith and in accordance with this policy. That means: make a genuine effort to avoid privacy violations, data loss, and interruption or degradation of our services; only access the minimum data needed to demonstrate the issue; do not modify or destroy data; and give us a reasonable time to respond before any public disclosure. If in doubt about whether a specific action is acceptable, ask us first.
In scope:
Out of scope
(please don’t test these, or report them elsewhere):
We publish security-relevant information on this site and in our release notes. Customers under a support agreement are notified directly of issues affecting their deployment. If a confirmed issue affects deployed versions, we notify affected customers within 5 business days of confirming impact; where an issue is being actively exploited, we notify within 24 hours. A software bill of materials (SBOM) of the components ProVide bundles is available to customers on request, so you can run your own dependency checks.
ProVide is a single, continuously maintained product. The latest release is the supported version; updates are opt-in, so you choose when to apply them, and your configuration migrates automatically. If a version ever reaches end of support, we will give at least 12 months’ advance notice and provide critical security patches for at least 12 months afterwards.
Because ProVide runs in your own environment, you (or a tester you appoint) are welcome to run security scans and penetration tests against your own instance at any time. We’re happy to cooperate, including providing a test instance and addressing confirmed findings under NDA.
ProVide is developed in alignment with the EU NIS2 directive and the EU Cyber Resilience Act (CRA), with secure development practices following OWASP guidance. ISO/IEC 27001 certification is targeted within the next one to two years.
For the ultimate experience of ProVide’s features and functions,
we recommend choosing the MAXI License.