Vulnerability handling procedure
Security vulnerabilities can be reported to our PSIRT at: psirt@inxpect.com
Reports are accepted from anyone, regardless of customer status, and no NDA is required.
All incoming reports are reviewed for completeness and relevance. We assess the technical details and, where necessary:
- Request additional information
- Involve engineering teams
- Coordinate with external CERTs or partners
During this phase, we maintain communication with the reporter.
Our engineering teams develop appropriate solutions to address the identified vulnerability. Depending on the case, this may include:
- Software or firmware updates
- Mitigation measures
- Risk reduction strategies
Once a solution is available or an agreed timeline is reached, a coordinated disclosure is performed. This typically includes:
- Publication of a security advisory
- Description of the vulnerability
- Recommendations for mitigation or update
Where applicable, contributors may be acknowledged.
Throughout the process, we aim to maintain:
- Transparent communication
- Professional collaboration with reporters
- Coordinated handling of disclosure timing
Security advisory
Access the tools to view vulnerabilities, security advisories, patches, and remediation information.