Vulnerability Policy

Coordinated Vulnerability Disclosure 

We are committed to maintaining the security of our products, services, and digital infrastructure. We welcome responsible vulnerability reports from security researchers, customers, partners, and other stakeholders. 

If you believe you have discovered a security vulnerability, we encourage you to report it to us so that we can investigate and take appropriate action. 

What to report 

We welcome reports regarding: 

  • Security vulnerabilities affecting our products or services. 
  • Vulnerabilities affecting our websites, systems, or online infrastructure. 
  • Security issues in third-party or open-source components used within our products where they may impact our customers or operations. 

How to report 

Please send your report to our Product Security Incident Response Team 

Email: psirt[at]aqualex.com

When reporting a vulnerability, please include: 

  • A clear description of the issue. 
  • The affected product, service, URL, or system. 
  • Steps to reproduce the vulnerability. 
  • Any supporting evidence, such as screenshots, logs, or proof-of-concept code. 
  • Your contact details if you would like us to follow up with you. 

Our commitment 

When you submit a report, we will: 

  • Acknowledge receipt of your report within a reasonable timeframe. 
  • Review and investigate the information provided. 
  • Treat vulnerability information confidentially. 
  • Keep you informed of significant progress where possible. 
  • Work to remediate validated vulnerabilities in a timely manner.  

Responsible research 

We ask researchers to: 

  • Act in good faith and avoid privacy violations, data destruction, service disruption, or exploitation of vulnerabilities beyond what is necessary to demonstrate the issue. 
  • Avoid accessing, modifying, or exfiltrating data that does not belong to you. 
  • Refrain from social engineering, phishing, denial-of-service attacks, malware deployment, or other activities that could negatively impact users or services. 
  • Give us reasonable time to investigate and remediate the vulnerability before publicly disclosing details.  

Safe Harbor 

We will not pursue legal action against individuals who discover and report vulnerabilities in good faith and in accordance with this policy. We ask that all testing remains limited to identifying and documenting the vulnerability and does not impact the confidentiality, integrity, or availability of our systems, products, or services.  

Recognition 

We appreciate the efforts of security researchers who help improve our security. With your consent, we may acknowledge your contribution in a security advisory or on a recognition page.  

Contact 

For questions regarding this disclosure policy or to report a vulnerability, please contact: psirt[at]aqualex.com