1. Purpose

Security is built into how we design, develop, maintain and support our products. This process explains how to report a security vulnerability in a Technetix product and how we handle it.

2. Scope

This process applies to applicable hardware products, embedded software, firmware, separately marketed software or hardware components, and associated remote data processing solutions developed by, or under the responsibility of, Technetix. 

3. How to report a vulnerability

To report a potential vulnerability, please email us at support@technetix.com with the details in section 4.

4. What to include in your report

  • Product or system name, model, version, and configuration, if known.
  • A clear description of the potential vulnerability and observed behaviour.
  • Steps to reproduce, proof of concept, logs, screenshots, or other supporting evidence.
  • Potential impact and known exploitation conditions.
  • Whether the issue has been disclosed to another party or assigned an identifier.
  • Any known disclosure deadline, embargo request, or coordinator involvement.
  • When the issue was discovered, and any signs that it is being actively exploited.

Please share only the minimum personal, customer, or confidential data needed to investigate.

5. What we will do

We will:

  • acknowledge your report as soon as reasonably practicable, and sooner for urgent reports;
  • assess the report;
  • where applicable, provide you with a case reference and a secure route for any further information that we may need; and
  • keep you updated on the progress and outcome.

6. Coordinated disclosure and embargo

We ask that non-public vulnerability information is not disclosed until the issue has been addressed. We will agree disclosure timing with you and any other relevant stakeholders.

Embargoes will not prevent us from making any notification or communication required by law.

For questions about this process please contact support@technetix.com