Product Security & Vulnerability Disclosure
Coordinated Vulnerability Disclosure
The security of our products is a top priority for the SITS Group. If you have discovered a potential vulnerability or security issue in a product of the SITS Group, please help us by reporting this information responsibly.
We carefully review every report and handle all submissions confidentially whenever possible.
What can you report?
- Security vulnerabilities in products of the SITS Group
- Vulnerabilities that could impact confidentiality, integrity, or availability
- References to publicly exploitable vulnerabilities
- Other security-relevant incidents or possible breaches
Please provide as much technical information as possible so that we can accurately reproduce and assess your report.
What information helps us process your report?
Helpful information includes (but is not limited to):
- Affected product
- Affected version
- Description of the vulnerability or incident
- Steps to reproduce
- Potential impact
- Screenshots, log files, or other technical evidence
How we handle reports
- Handling incoming reports confidentially
- Carefully reviewing every reported issue
- Protection of the reporter's personal data
- Maintaining open and professional communication with reporters
- Coordinating the disclosure of vulnerabilities after remediation
Response Times
Provided that all required information has been submitted, the following target timelines apply:
| Feedback | Response Time |
| Initial response | Within 5 business days |
| Status update / feedback | Within 10 business days |
Vulnerability Disclosure Policy
Detailed information about our process for vulnerability reports and coordination can be found in our Vulnerability Disclosure Policy.
Report a Vulnerability
Report via Email
If you do not wish to use the web form, you can also contact us directly at: 📧psirt@sits.com
Report via Web Form
You are currently viewing a placeholder content from HubSpot. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information