Coordinated Vulnerability Disclosure
Securosys is committed to the security, integrity, and resilience of its products, services, and infrastructure. Protecting cryptographic assets, sensitive data, and customer environments is central to our mission. Security is embedded across product design, development, operations, and service delivery.
We actively support coordinated vulnerability disclosure and welcome reports from security researchers, customers, and partners. External security research plays an important role in identifying and addressing potential weaknesses and improving overall security posture.
This Coordinated Vulnerability Disclosure (CVD) statement explains how vulnerabilities can be reported to Securosys and how such reports are handled in a structured and responsible manner.
Reporting a Security Vulnerability
Security vulnerabilities can be reported to Securosys Security Team (PSIRT, CSIRT).
Please include, where possible:
- Contact details for follow-up (name, organization if applicable).
- A clear description of the issue and its potential security impact.
- Affected product, service, component, or version.
- Steps to reproduce the issue, including relevant configuration and environment details.
- Supporting materials such as logs, screenshots, or network traces.
- Proof-of-concept code, if applicable and safely shareable.
- Information on whether the issue has been reported to other parties (e.g., CERTs) and any tracking references.
- Any planned public disclosure aligned with Securosys.
Reports should preferably be submitted in English to ensure efficient processing.
Any sensitive non-public information about vulnerabilities is considered highly confidential, and only individuals who have a legitimate need to know and can add value to the remediation process may access this information until notification. By submitting a report, you grant Securosys the right to use the information provided solely for the purpose of investigating, remediating, and disclosing the reported vulnerability. Submission does not create any contractual obligation or intellectual property rights beyond what is described in this policy.
Sensitive information should be protected during transmission, for example using encryption with the Securosys PGP public key where applicable.
PGP Key for Securosys Security Team (PSIRT, CSIRT)
Fingerprint: BF28 35CC C324 14A8 8C05 5294 F0EE 4B0E 9AB4 D43C
Not sure where to report?
Pick the channel that matches the nature of your finding:
-
PSIRT – Product Security Incident Response Team
Report vulnerabilities found in Securosys products — firmware, hardware (HSMs), cloud services (CloudHSM), or APIs.
-
CSIRT – Computer Security Incident Response Team
Report security issues affecting Securosys's own IT infrastructure, internal business applications, web properties, or cloud-hosted services — e.g. the corporate website, support portal, customer-facing web applications, or internal systems.
Securosys Handling Process
Securosys is committed to handling every report promptly, transparently, and in close collaboration with the reporter. Once a report is received, we will:
- Acknowledge receipt within two business days and assign a tracking reference and responsible contact.
- Validate and assess the reported vulnerability, including severity and affected scope.
- Engage relevant engineering teams for analysis and remediation.
- Provide regular status updates throughout the investigation and resolution process.
- Deliver fixes, mitigations, advisories, or guidance as appropriate to the severity and impact.
- Notify the reporter when the vulnerability has been resolved or mitigated.
- Coordinate public disclosure with the reporter, agreeing on timing and scope where appropriate.
- Recognize eligible researchers in the Securosys Hall of Honor, subject to consent.
Resolution timelines depend on severity, complexity, and customer impact considerations. Securosys may also involve third-party vendors when affected components are outside our direct control.
Responsible Disclosure Principles
Securosys follows a responsible and coordinated disclosure model to ensure vulnerabilities are properly assessed and mitigated before public release.
After validation of a reported issue, Securosys may engage with the reporter to agree on an embargo period and coordinated disclosure timeline. This helps reduce risk exposure for customers and users while enabling effective remediation.
Researchers participating in this process are expected to adhere to the following principles:
- Do not exploit vulnerabilities beyond what is necessary to demonstrate their existence.
- Do not access, modify, delete, or exfiltrate data beyond minimal proof-of-concept requirements.
- Do not disclose vulnerability details publicly before remediation and without explicit agreement from Securosys.
- Do not perform disruptive or intrusive activities such as denial-of-service attacks, social engineering, phishing, physical intrusion, spam, or attacks against third-party systems.
- Do not use vulnerabilities for unauthorized access, personal gain, or any activity that could harm Securosys, its customers, or partners.
Scope
This policy applies to vulnerabilities affecting all our products that have not reached End-of-Life (EoL) milestone:
- Securosys Hardware Security Modules (HSMs).
- Securosys software, firmware, and management interfaces.
- Securosys cloud services and platforms.
- Securosys-operated websites and APIs.
- Any other Securosys-owned or operated products and services.
Issues in third-party components integrated into Securosys solutions may be forwarded to the respective vendor, where applicable.
Recognition
Securosys appreciates the contributions of the security research community. Valid and previously unknown vulnerabilities may be acknowledged in the Securosys Coordinated Vulnerability Disclosure Hall of Honor, subject to the researcher’s consent.
Safe Harbor
Securosys will not initiate legal action against individuals who:
- Act in good faith and in accordance with this policy.
- Avoid harming customers, systems, or services.
- Report vulnerabilities responsibly and cooperate in remediation.
- Refrain from unauthorized or destructive activities.
Thank You
Securosys genuinely values the work of security researchers. When you report a vulnerability to us, you are helping protect our customers' most sensitive cryptographic assets. We commit to working with you transparently, keeping you informed as we investigate and remediate, and notifying you when a fix is confirmed.
We thank you for contributing to a more secure ecosystem.
