Skip to main content

Thank you for taking the time to help us maintain the security and integrity of our products, systems, and services.
We are committed to identifying, assessing, and addressing cybersecurity vulnerabilities in a responsible and timely manner. This Vulnerability Disclosure Policy explains how security researchers, customers, and other stakeholders can report potential security vulnerabilities to us and how such reports are handled.
This policy also supports our compliance efforts in relation to applicable cybersecurity legislation, including the EU Cyber Resilience Act (CRA), and demonstrates our commitment to cybersecurity throughout the lifecycle of our products.

Reporting a vulnerability
If you believe you have identified a security vulnerability in one of our products, services, websites, or systems, we encourage you to report it to us as soon as possible using Vulnerability Report Form.
When submitting a vulnerability report, please include:

  • A detailed description of the vulnerability.
  • The affected product, service, or system.
  • Information necessary to reproduce the issue.
  • The potential impact of the vulnerability.
  • Attack vectors
  • References
  • When it occurred
  • Where it occurred
  • Other comments

Our commitment
When a vulnerability is reported to us, we will:

  • Acknowledge receipt of the report within a reasonable timeframe.
  • Assess and validate the reported vulnerability.
  • Prioritise remediation activities based on the severity and potential impact of the issue.
  • Maintain communication with the reporter when appropriate.
  • Take reasonable steps to resolve verified vulnerabilities.

We appreciate responsible disclosure and value the contribution of individuals who help improve the security of our products and services.


We comply with the CRA guidelines for responding to vulnerabilities within the deadlines, depending on the severity and vulnerability of the report.

Responsible disclosure guidelines
To help protect our customers, users, and business operations, we ask that anyone reporting a vulnerability:

  • Act in good faith and avoid actions that may harm users, products, services, or data.
  • Do not exploit a vulnerability beyond what is necessary to demonstrate its existence.
  • Do not access, modify, disclose, or delete data that does not belong to you.
  • Do not attempt to disrupt, degrade, or compromise our services or systems.
  • Provide us with a reasonable opportunity to investigate and address the issue before publicly disclosing information about the vulnerability.

Activities that result in privacy violations, service disruption, data destruction, or other unlawful conduct are not authorized under this policy.
Scope

This policy applies to vulnerabilities identified in products, software, services, websites, and systems owned or operated by us.
The policy does not authorize testing activities that violate applicable laws, regulations, contractual obligations, or third-party rights.