Product vulnerability disclosure notice
Introduction
We are committed to maintaining the security, safety, and reliability of our products, solutions, and services.
We welcome reports from customers, security researchers, partners, suppliers, and other external parties who identify potential security vulnerabilities affecting our products or associated services. Responsible reporting helps us investigate, assess, and remediate security issues in a timely manner.
This Vulnerability Disclosure Policy explains how to report a potential vulnerability, what information should be included in a report, and how we will handle your submission.
We do not operate a bug bounty program and do not provide financial rewards for vulnerability submissions.
Scope
This policy applies to potential cybersecurity vulnerabilities affecting our products and their associated digital components, including software, firmware, and hardware.
This policy does not authorize security testing, penetration testing, scanning, or any other activity that may disrupt operations by impacting confidentiality, integrity, or availability of our products, services, systems, customers, or data.
How to contact us?
If you believe you have discovered a security vulnerability affecting one of our products or services, please submit a report using the report form available on this page. A member of the Product Security Incident Response Team (PSIRT) may contact you if additional information is required or to provide updates regarding the status of your report.
We aim to acknowledge reports within a reasonable timeframe and keep reporters informed throughout the investigation process where possible.
What shall the report contain?
Contact information: Your name, email, phone number (optional) and organization (if applicable).
Type of Report: Select Vulnerability / Incident depending on the circumstances you wish to report.
Affected Product or Service: Name of the product or service, and if available, the product’s number, SKU or serial number of the machine.
Description: A detailed description of the identified potential vulnerability. Where possible include technical details regarding the issue, steps required to reproduce the vulnerability, conditions required for exploitation, potential impact of the vulnerability.
Attachment(s): Where possible, please provide supporting information such as, screenshots, log files, network traces, proof-of-concept code, or other relevant documentation.
Please do not include, in this initial report, any personal data, or other sensitive information unless you believe it is necessary in the context required to explain the potential vulnerability in this Initial Report. If there is a need to securely exchange sensitive files, the PSIRT team will set up a secure environment for future information exchange.
How do we handle your report?
Acknowledgement
Upon receipt of a Report submission, you will receive an automated email confirmation acknowledging that the report has been successfully submitted.
Investigation
The reported vulnerability will be investigated by the appropriate teams within our organization. Depending on the nature of the issue, this may involve product security specialists, engineering teams, product owners, and, where applicable, privacy and data protection specialists.
We will contact the reporter if additional information is required to support the investigation.
Communication
The PSIRT team will maintain communication with the reporter regarding the status of the investigation and any actions being taken.
Resolution
The outcome of the investigation and any remediation measures will be communicated to the reporter and, where applicable, to relevant authorities, affected users, and other relevant stakeholders.
Where we become aware of an actively exploited vulnerability or a severe incident affecting the security of a product, we will inform impacted users and, where appropriate, all users of the affected product, of the vulnerability or incident and any risk mitigation or corrective measures that users can take.
Responsible Disclosure Expectations
We ask reporters to act responsibly and in good faith when reporting potential vulnerabilities. Specifically, we ask that you:
• Avoid actions that could negatively impact customers, products, services, or business operations.
• Do not intentionally access, modify, copy, delete, or disclose data that does not belong to you.
• Do not attempt to disrupt the availability of products, systems, or services.
• Cooperate with us during the investigation and remediation process where clarification is required.
Coordinated Disclosure
We request that reporters do not publicly disclose details of a vulnerability until, we have been able to complete our internal investigation and remediation activities, unless a mutually agreed disclosure date has been established.
Where appropriate, we may publish security recommendations, patch notes, or other communications to inform customers about identified vulnerabilities and available remediation measures.
Safe Harbor
We will not seek to pursue legal action against individuals who, in good faith:
• Identify and report vulnerabilities under this policy;
• Act responsibly and avoid causing harm;
• Respect applicable laws and regulations; and
• Cooperate with us to investigate and remediate reported issues.
This statement does not apply to activities that intentionally cause harm, result in unauthorized access to data, violate privacy rights, disrupt services, or otherwise breach applicable laws or regulations.
Privacy
We process personal data provided in vulnerability reports solely for the purposes of receiving, investigating, coordinating, and resolving reported security vulnerabilities and for communicating with reporters.
For privacy-related questions, or to better understand how we process personal data and your privacy rights, please refer to our Privacy Policy.