The security policy today allows (among other entities) “Public hosting providers” and “Large-scale organisational users of Xen” to join the predisclosure list (the latter having specific criteria).
A recent application (https://lists.xenproject.org/archives/html/predisclosure-applications/2026-05/msg00000.html) highlights an ‘intermediate’ case - that is someone using a product based on Xen to provide an application to the public (for a fee in this case), but where they are not directly offering ‘hosting’ as the service.
This session is to discuss whether and if so how to modify the policy to accommodate this case.