Inxpect psirt page 1

Product Security Incident
Response Team

Inxpect is committed to maintaining the security of its products and welcomes the contribution of external security researchers and customers. Inxpect encourages the responsible disclosure of any security vulnerabilities that may be identified in our products or services.

Scope

This policy applies to all systems, services and products owned or operated by Inxpect. It outlines the process for reporting vulnerabilities and our commitment to reviewing and responding to such reports.

Reporting a vulnerability

If you believe you have discovered a security vulnerability, we ask you to report it to us as soon as possible using the following contact:

psirt@inxpect.com

All communications and reports must be provided in English to ensure efficient and consistent processing.
To allow us to efficiently assess, reproduce, and address the issue, we ask that your report includes sufficient technical detail and context. In particular, please ensure that the following information is provided:

  1. Product identification, including part number or model/type reference, as well as the relevant hardware or software version.
  2. A complete technical description of the potential vulnerability, including any known exploits or proof-of-concept materials, if available.
  3. An explanation of how and when the vulnerability was discovered, including any relevant circumstances or methods used.
  4. Details of any publicly available information or planned disclosures, such as CVE assignments, academic publications, or conference papers.
  5. Your contact information, so that we can communicate with you throughout the entire handling process.

Providing this information helps us to reproduce the issue accurately, assess its potential impact, and define the appropriate remediation actions in a timely manner. Where certain details are not immediately available, we still encourage you to submit the report and provide additional information during the investigation process.

Vulnerability handling procedure

Security vulnerabilities can be reported to our PSIRT at: psirt@inxpect.com
Reports are accepted from anyone, regardless of customer status, and no NDA is required.

All incoming reports are reviewed for completeness and relevance. We assess the technical details and, where necessary:

  • Request additional information
  • Involve engineering teams
  • Coordinate with external CERTs or partners

During this phase, we maintain communication with the reporter.

Our engineering teams develop appropriate solutions to address the identified vulnerability. Depending on the case, this may include:

  • Software or firmware updates
  • Mitigation measures
  • Risk reduction strategies

Once a solution is available or an agreed timeline is reached, a coordinated disclosure is performed. This typically includes:

  • Publication of a security advisory
  • Description of the vulnerability
  • Recommendations for mitigation or update

Where applicable, contributors may be acknowledged.

Throughout the process, we aim to maintain:

  • Transparent communication
  • Professional collaboration with reporters
  • Coordinated handling of disclosure timing

Secure Communication (Recommended)

Because of the sensitive nature of vulnerability reporting, we strongly encourage the use of encrypted communication when submitting reports.

Where possible, please use our PGP public key to encrypt your message and send it to psirt@inxpect.com

Resources
Fingerprint DE38B9A1F1C749032A8397310111650187E43D99
Inxpect psirt page 2

Security advisory

Access the tools to view vulnerabilities, security advisories, patches, and remediation information.

Go to Inxpect Tools

Inxpect commitment

Once a vulnerability report has been received, it will be handled by our Product Security Incident Response Team (PSIRT) in a structured, confidential, and risk-based manner.

We are committed to ensuring that all reports are properly acknowledged and assessed, and that appropriate actions are taken based on the severity and impact of the issue. In particular, Inxpect aims to:

  • Acknowledge receipt of the report within 5 business days
  • Provide regular updates during the investigation and remediation process
  • Work towards the development and release of a corrective solution whenever necessary
  • Maintain open and professional communication with the reporter throughout the process
  • Process the personal data you provide (name, email address) in accordance with applicable data protection legislation.

Our objective is to ensure that vulnerabilities are addressed effectively while minimizing risk to customers and end users.

Legal Notice and Rights

Inxpect takes all vulnerability reports seriously. By submitting a report, you confirm that you have the right to do so and that the information provided does not infringe any third-party rights.

By submitting a vulnerability report, you grant Inxpect S.p.A the rights to use the submitted information for purposes related to:

  • Security analysis and technical evaluation
  • Vulnerability reproduction and testing
  • Development of corrective measures and patches
  • Reporting and disclosure activities
  • Any other activities directly related to product security improvement

This ensures that the report can be processed effectively and used solely for the purpose of improving Inxpect products and services.

Inxpect does not pursue legal action against individuals who report vulnerabilities in good faith and in accordance with this policy, avoiding actions that could harm  its systems, services or data. 

This commitment does not constitute a waiver of any rights or remedies available to Inxpect S.p.A. under applicable law. Inxpect S.p.A. reserves the right to take appropriate action where activities are conducted in bad faith, with malicious intent, unlawfully, or outside the scope of this Policy.

Out of Scope

The following activities are considered out of scope and must not be performed in connection with vulnerability research or reporting under this Policy, unless expressly authorized in advance by Inxpect S.p.A.:

  • Denial-of-Service (DoS/DDoS) attacks or activities intended to disrupt or degrade the availability of products or services;
  • Social engineering, phishing or other attempts to deceive or manipulate individuals;
  • Brute-force attacks or other attempts to obtain or compromise credentials;
  • Activities that may damage, disrupt or threaten the confidentiality, integrity or availability of Inxpect products, services, systems or data;
  • Unauthorized access to, modification, extraction or disclosure of data; 
  • Public disclosure or sharing of vulnerability information with third parties without prior coordination with Inxpect S.p.A.