Zum Inhalt springen
24/7-Notfall-Hotline
de
Leistungen
Lösungen
Forschung
Unternehmen
ToolsTrust Center

Trust Center

Responsible Disclosure

How we report vulnerabilities we find in other vendors’ products.

1 Min. Lesezeit

Dieser Inhalt ist derzeit nur auf Englisch verfügbar.

When our research or customer engagements uncover a vulnerability in a third-party product, we follow responsible disclosure principles. Vulnerabilities found during customer engagements are never shared with third parties without the customer’s consent.

  1. Day 0

    01

    Report

    The vendor is notified through its official security contact with full technical details.

  2. Process

    02

    Coordination

    We work with the vendor on a fix timeline and coordinate a CVE where needed.

  3. Day 90

    03

    Publication

    Technical details may be published once a fix is released or after 90 days.

Exceptions

For vulnerabilities under active exploitation, the timeline may be shortened to protect users. Reasonable extension requests from vendors are considered in good faith.