Report a security issue

FireGiant welcomes good-faith reports about security vulnerabilities in our products, services, and software supply chain.

Product security contact

[email protected]

Please use this address for confidential vulnerability reports.

What is in scope

FireGiant products and services, including WiX Toolset and HeatWave.

Reports may also concern release, build, signing, distribution, update, or integrated third-party components.

Secure reporting

Do not include unnecessary personal data.

For sensitive attachments or proof-of-concept material, contact us first for a secure transfer method.

What to include

These details help us assess a report. They are recommended, not required; incomplete reports are welcome.

What is affected?

Name the product, service, component, or version. Include a build, commit, package, or other identifier when available.

What is the impact?

Describe the weakness, what an attacker could achieve, and any required preconditions or known affected environments.

How can we reproduce it?

Include reproduction steps, proof of concept, logs, and the tested environment where safe to do so.

Is it being exploited?

Tell us about suspected or confirmed exploitation, planned publication, or coordination with others.

Who else may be affected?

Include relevant deployment details and whether the issue may affect maintainers, suppliers, or other third parties.

How can we follow up?

A name, email address, or pseudonym is helpful. You may report without identifying yourself.

How we handle reports

Our process is risk-based and may vary with the nature and urgency of the issue.
  • Acknowledge and triage. We review the report, determine whether it concerns a security issue, and may request additional information.
  • Investigate and coordinate. We validate the issue and coordinate with reporters, maintainers, and affected suppliers when appropriate.
  • Remediate and communicate. We work on risk-based corrective or mitigating measures and keep the reporter informed when practical.
  • Disclose responsibly. When appropriate, we publish an advisory after users have had a reasonable opportunity to apply a fix or mitigation.
Where required by law, FireGiant may separately notify relevant authorities and users. A reporter does not need to submit a regulatory notification on FireGiant's behalf.

Good-faith research

Please avoid unnecessary disruption, privacy intrusion, destruction of data, or access beyond what is needed to demonstrate the issue. Do not publicly disclose a suspected vulnerability while it is being assessed or remediated unless coordinated with FireGiant.

This page describes FireGiant's expectations and process. It is not a bug bounty, compensation offer, or legally binding safe harbor, and it does not change any legal rights or obligations.

Coordinated vulnerability disclosure

This page is FireGiant's public process for receiving and coordinating reports about vulnerabilities in FireGiant products and related components.

Not a security issue?

For licensing questions, installation problems, build errors, and general defects, use our contact page or the relevant product support channel.