Scope

The following describes how and when we resolve security bugs in our products. It does not describe the complete disclosure or advisory process that we follow.

Security bug fix Service Level Agreement (SLA)

We have defined the following timeframes for fixing security issues in our products:

The following critical vulnerabilities resolution policy excludes our Cloud products, as these services are always fixed by Atlassian without any additional action from customers.

Critical Vulnerabilities

When a Critical security vulnerability is discovered by Xpand IT or reported by a third party, Xpand IT will do all of the following: