Loading

Security Policy

Last Updated: 30-Jun-2026

Farsight Tech Nordic builds ProVide with security as a foundation, not an afterthought. This page explains how to report a security issue, what you can expect from us in return, and how we handle security updates and advisories. It is the policy referenced by our security.txt.

REPORTING A VULNERABILITY

If you believe you’ve found a security vulnerability in ProVide or on our website, please tell us privately at security@provideserver.com. We accept reports in English or Swedish.

To help us assess and reproduce the issue quickly, please include where you can:

  • the affected product and version (or the URL, for the website);
  • a description of the issue and its potential impact;
  • step-by-step instructions to reproduce it, with any proof-of-concept;
  • how you’d like to be credited, if you wish to be.

If you need to share sensitive details, contact us first and we’ll arrange a secure channel. Please give us a reasonable opportunity to investigate and release a fix before disclosing the issue publicly. We’re committed to working with you on coordinated disclosure.

WHAT YOU CAN EXPECT FROM US:

  • We will acknowledge your report within 2 business days.
  • We will validate the issue, keep you informed of our progress, and let you know when it’s resolved.
  • We aim to remediate confirmed issues on the following targets, by severity (CVSS): Critical within 7 days, High within 30 days, Medium in the next scheduled release, Low in a future release.
  • With your permission, we’re glad to publicly credit your contribution.

We do not currently operate a paid bug-bounty program.

SAFE HARBOUR:

We will not pursue or support legal action against researchers who act in good faith and in accordance with this policy. That means: make a genuine effort to avoid privacy violations, data loss, and interruption or degradation of our services; only access the minimum data needed to demonstrate the issue; do not modify or destroy data; and give us a reasonable time to respond before any public disclosure. If in doubt about whether a specific action is acceptable, ask us first.

SCOPE:

In scope:

  • ProVide Server, ProVide Gateway, and ProVideLink;
  • official ProVide downloads from provideserver.com;
  • the provideserver.com website.

Out of scope
(please don’t test these, or report them elsewhere):

  • third-party libraries, services, or platforms. Report those to their respective vendors (we track and patch the components we bundle separately);
  • volumetric denial-of-service, traffic generation, or load testing;
  • social engineering of our staff or customers, and physical attacks;
  • findings that require an already-compromised, rooted, or jailbroken host;
  • automated scanner output with no demonstrated, exploitable impact, or general best-practice suggestions without a concrete security effect.

SECURITY ADVISORIES AND CUSTOMER NOTIFICATION:

We publish security-relevant information on this site and in our release notes. Customers under a support agreement are notified directly of issues affecting their deployment. If a confirmed issue affects deployed versions, we notify affected customers within 5 business days of confirming impact; where an issue is being actively exploited, we notify within 24 hours. A software bill of materials (SBOM) of the components ProVide bundles is available to customers on request, so you can run your own dependency checks.

SECURITY UPDATES AND SUPPORTED VERSIONS:

ProVide is a single, continuously maintained product. The latest release is the supported version; updates are opt-in, so you choose when to apply them, and your configuration migrates automatically. If a version ever reaches end of support, we will give at least 12 months’ advance notice and provide critical security patches for at least 12 months afterwards.

Because ProVide runs in your own environment, you (or a tester you appoint) are welcome to run security scans and penetration tests against your own instance at any time. We’re happy to cooperate, including providing a test instance and addressing confirmed findings under NDA.

STANDARDS:

ProVide is developed in alignment with the EU NIS2 directive and the EU Cyber Resilience Act (CRA), with secure development practices following OWASP guidance. ISO/IEC 27001 certification is targeted within the next one to two years.

SECURITY:

YOUR CART

CUSTOMERS ALSO ADD

HAVE A COUPON?
ORDER SUMMARY
We'll send a tailored quote to your inbox.

The invoice will be e-mailed once your order is confirmed.

ProVide Server

Your cart is empty

maxi_provideserver

Choose your version of ProVide Server to download

For the ultimate experience of ProVide’s features and functions,
we recommend choosing the MAXI License.

Follow the 3 easy steps below to install ProVide Server
  1. Download the version you need using the buttons below.
  2. Get a free MAXI trial license by clicking the “Get Maxi Trial License” button and enter your email. The license key will be sent to your email.
  3. Activate the license key by following this simple step-by-step-guide.

Free Trial

Get
ProVide Software