Securosys PSIRT Contact Form
Use this form to report suspected security vulnerabilities in Securosys products, firmware, cloud services, or APIs. Reports are handled by the Securosys Product Security Incident Response Team (PSIRT), treated as strictly confidential, and reviewed by within two business days.
For details on how reports are processed, see the Securosys Coordinated Vulnerability Disclosure Policy.
Vulnerabilities in scope
- Cryptographic key extraction or bypass
- Authentication or authorization flaws
- Undisclosed HSM access methods
- Hardcoded or undocumented credentials
- Firmware integrity bypass
- Privilege escalation in management interfaces
- PKCS#11 or REST API injection flaws
- Insecure key storage or key leakage
- TLS/certificate validation failures
- Side-channel attacks on crypto operations
- Cross-site scripting or CSRF in web consoles
- Bypass of tamper-resistance mechanisms
For issues with the Securosys corporate website, support portal, or internal systems (not products), please use the CSIRT Reporting Contact Form.
