Tanium Vulnerability Disclosure Policy
Tanium takes security very seriously, therefore our security engineering team promptly acknowledges, investigates and fixes every legitimate vulnerability report we receive.
Tanium’s Commitment to Security and Transparency
Tanium is proud to operate as a CVE Numbering Authority (CNA) under MITRE’s globally recognized Vulnerability
Disclosure Program. This designation reflects our deep commitment to transparency, security, and collaboration with
the broader cybersecurity community.
As a CNA, Tanium is authorized to assign CVE identifiers to validated vulnerabilities in our products and services.
This role enhances our ability to support customers and partners by providing timely, structured, and publicly
accessible vulnerability information. Our participation in the CVE program ensures that security researchers,
customers, and industry stakeholders can rely on a consistent and trusted process for vulnerability disclosure.
The Tanium CNA will issue CVEs that support customers in addressing valid security vulnerabilities within the
following classes:
- Security vulnerabilities in the Tanium Platform, products and solutions that have been commercially released and
are currently supported. - Vulnerabilities in Tanium-owned systems and services involved in the hosting of Tanium Cloud, which are not
explicitly related to an individual customer. - Vulnerabilities in Tanium’s implementation of third-party technologies / libraries.
We believe partnering with the security community benefits our customers and our software, and, therefore, we have a
Bug Bounty program that provides rewards to researchers who disclose security vulnerabilities in a responsible
manner. See the Vulnerability Terms and Conditions linked below for additional details regarding eligibility and
scope.
If you have identified a vulnerability that is in scope for either Tanium’s CNA or Bug Bounty programs under the
Tanium Vulnerability Reporting Terms and Conditions please report the issue to Tanium Product Security using the
HackerOne submission form below.
Our security engineering team promptly acknowledges, investigates and remediates every legitimate vulnerability
report we receive.
Response Targets
If you identify and submit a security vulnerability in compliance with these Terms, we will use reasonable
efforts to meet the following response targets:
Time to first response – 2 business days from first submission
Time to initial triage - 72 hours from first submission
Time to resolution, including potential mitigation and fixes, as well as security advisory - will vary
depending on the severity and complexity of the vulnerability
Tanium will update researchers about the progress of our review during the response process. Upon
request, Tanium will acknowledge the reporter of a vulnerability in our public security bulletins. If
you wish to include information about a Tanium vulnerability on a public website or other medium, we ask
that you work with us to coordinate the disclosures.
Providing a secure and reliable platform for our customers is our top priority so we encourage anyone who discovers a security vulnerability or issue to immediately report it. Please include as much information as possible, such as version information, proof-of-concept code or special configurations that will help us validate and reproduce the issue.