Security Policy

Last updated: 2026-06-05

At CadenzaFlow, we are committed to Information Security, Privacy, and Compliance. Our mission is to establish trust through transparency.

Just as Camunda forked from Activiti 5.10 in early 2013, CadenzaFlow forked from Camunda 7.24 in late 2025.

Since then, following the CadenzaFlow Release Cycles, a Vulnerability Report is provided with every CadenzaFlow BPM Platform release in the Roadmap under the Security Section.

Vulnerability Reporting

The CadenzaFlow team utilizes Trivy to generate vulnerability reports.

The baseline vulnerability state of Camunda 7.24, along with the progress made in each CadenzaFlow release (v1.1.0, v1.2.0, etc.), can be found under the Security Section.

Reporting Security Issues

For any security-related issues, we recommend contacting the CadenzaFlow team. Security issues and vulnerabilities can be reported as described below.

  • Fill out the Security Issues Reporting Form below.
  • Provide in the
    • Severity: CRITICAL|HIGH|MEDIUM|LOW,
    • Title: short description of issue
    • Description: A detailed description of the security issue. Please include as many relevant details as possible.

Security Issues Reporting Form

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
  • Once reported, the CadenzaFlow team will respond with a tracking issue number under CadenzaFlow BPM Issues and will handle the report according to the CadenzaFlow Security Issue Process.
    Please note that some details provided in the email may be hidden or masked in the issue for security and privacy reasons.

Vulnerabilities discovered by Community users are treated as bugs and addressed on a best-effort basis.

Vulnerabilities discovered by Enterprise customers are treated according to the agreed support and SLA terms.

Security notices (Vulnerability Reports) for each CadenzaFlow release can be found at: TODO.

Qualification

Once reported, the CadenzaFlow team assesses the vulnerability. This includes root cause analysis, as well as evaluating the risk and impact of the issue. This assessment is performed in close collaboration with the reporter.

Remediation

The CadenzaFlow team creates a remediation plan to address identified security issues. Fixes are made available through:

  • Patch releases (Enterprise customers only)
  • Alpha/minor releases (Community platform users)

Announcement

Once a fix is released or a practical workaround becomes available, the CadenzaFlow team announces users through the relevant Vulnerability Reports page.