last updated August 28, 2026

Security and Vulnerability Disclosure

1. Reporting

1.1If you have found a security issue in Proxploy or on this website, email security [at] aspyrelabs [dot] com. It is monitored.

1.2Please include enough detail for us to reproduce the issue: affected version, the steps you took, and what you observed. If you have a proof of concept, send it. Please do not open a public issue for a security report.

1.3Proxploy manages hypervisors and holds credentials for them, so we would rather hear about a suspected issue that turns out to be nothing than not hear about a real one. Report it even if you are unsure.

2. What we commit to

2.1We will acknowledge your report within 5 business days.

2.2We will tell you whether we have accepted the report, keep you updated as we work on it, and let you know when a fix ships.

2.3We aim to publish a fix and an advisory within 90 days of accepting a report. If an issue is being actively exploited we will move faster; if a fix is genuinely harder than that, we will tell you where it stands rather than go quiet.

2.4If you would like to be credited in the advisory, say so in your report and we will credit you. If you would rather stay anonymous, that is fine too.

3. Safe harbour

3.1We will not pursue or support legal action against you for security research conducted in good faith under this policy. We consider such research to be authorised, and we will say so if a third party suggests otherwise.

3.2Good faith means: you test only against systems you own or are permitted to test, you do not access, modify, or destroy data that is not yours, you do not degrade service for anyone else, and you give us a reasonable opportunity to fix the issue before disclosing it publicly.

3.3If you follow this policy and inadvertently break something, tell us. We will treat that as part of good-faith research rather than as a breach of it.

4. Scope

4.1In scope:

  • the Proxploy software, at its current release;
  • the installer published at this site and the release artifacts it fetches;
  • this website and its infrastructure.

4.2Out of scope:

  • your own Proxmox hosts, network, and installation, which are yours to secure and which we have no access to;
  • vulnerabilities in Proxmox VE itself, which belong to Proxmox, and in third-party community scripts installed through the App Store, which belong to their maintainers;
  • denial of service, volumetric or resource-exhaustion testing, and social engineering of us or our users;
  • reports produced by a scanner with no demonstrated impact, and findings that amount to missing hardening headers with no exploitable consequence.

5. Rewards

5.1We do not run a paid bounty programme, and we would rather say that plainly than imply one. What you get is a fast, human response, credit if you want it, and a fix.

6. Release integrity

6.1Each Proxploy release publishes a manifest alongside the release artifact, giving the artifact’s SHA-256 checksum, together with a detached signature over that manifest. If a download does not match, do not install it, and tell us.

7. Contact

7.1Security reports: security [at] aspyrelabs [dot] com. For anything that is not a security issue, the addresses on our About page will reach us faster.