Securosys CSIRT Contact Form
The Securosys Computer Security Incident Response Team (CSIRT) is responsible for the security of Securosys's own IT infrastructure, internal business applications, web properties, and cloud-hosted services. Use this form to report security issues affecting the Securosys corporate website, support portal, customer-facing web applications, or internal systems.
The CSIRT team investigates and remediates issues in Securosys-operated infrastructure and applications. All reports are treated confidentially and reviewed by the CSIRT within two business days.
For details on how reports are processed, see the Securosys Coordinated Vulnerability Disclosure Policy.
The following categories are considered low-priority or out of scope for the Securosys CSIRT Responsible Disclosure Programme:
- Theoretical vulnerabilities without proof of concept
- Missing X-Frame-Options / clickjacking with no impact
- Automated scanner output not manually validated
- Incomplete or missing SPF / DMARC / DKIM records
- Low-severity informational disclosures
- Account enumeration via brute force
- Self-XSS (user-defined payload)
- Browser autocomplete / saved credentials
- Network-level DoS / DDoS
- Verbose error pages without exploitability proof
- Physical intrusion or social engineering attempts
- SSL/TLS best-practice issues without functional PoC
- Low-impact session management issues
- Missing cookie flags without demonstrated impact
- Unchained open redirects
- UI/UX bugs and spelling mistakes
- Exposed login pages (no vulnerability)
- Low-impact content spoofing
- Directory listings without sensitive content
Out of scope — will not be eligible for acknowledgement unless high impact is demonstrated.
Reporting a vulnerability in a Securosys product or firmware (PrimusHSM, CloudsHSM, PKCS#11, REST API, MCP Server, etc.)? Please use the Securosys PSIRT Reporting Contact Form instead.
