Security is integrated into our product development process to help protect customers and their connected environments.
We carefully review, assess, and follow up on every submitted vulnerability report.
We aim to acknowledge every submitted vulnerability report within two business days.
We provide timely progress updates and request further information when needed.
We address reported vulnerabilities throughout each product’s stated security support period.
Magewell appreciates security research conducted in good faith. This policy explains how to report potential vulnerabilities and the protections available for good-faith research.
Magewell welcomes reports of potential security vulnerabilities and encourages responsible disclosure through the reporting channels on this page.
Magewell will not initiate legal action against researchers who conduct good-faith security research in accordance with this policy. This protection applies only to claims under Magewell’s control and does not authorise unlawful activity or bind third parties.
Magewell follows a structured process to ensure that each vulnerability report is handled appropriately:
We acknowledge and register the report for tracking and follow-up.
We reproduce the issue and assess its severity and impact.
We develop and validate an appropriate fix or mitigation.
We provide updates and communicate the resolution through official channels.
Magewell provides security support according to the lifecycle and applicable security support period of each product.
Products currently offered for sale receive security support throughout their stated support period.
Discontinued products within their stated support period continue to receive security fixes.
Products beyond their stated support period no longer receive routine security updates.
The support period starts from the date the product is placed on the Union market. Please refer to the packaging box for more details.
You can report a potential security vulnerability through our online submission form or by email.
Mailbox: support@magewell.net
You may send a standard email without encryption. Please include the information listed below so that we can investigate and respond effectively.
If your report contains sensitive information, we recommend encrypting it using our public PGP key before sending.
Key ID: D38278DD; Fingerprint: EA4A 1F9F 814E 99A4 8F4F F8B0 5FBD 6760 D382 78DD
Download PGP Public KeyPlease remove unrelated personal or confidential information from all submitted materials. Do not send passwords, private keys, or personal data that is not necessary to investigate the issue.
By clicking, you agree to our Vulnerability Reporting Policy and commit to not disclosing any vulnerability details to external parties before the vulnerability is fixed.