Our security / vulnerability disclosure
Security / Vulnerability Disclosure
We value the security of our products and services.If you believe you have identified a security vulnerability, please report it to us at: security@photonfirst.com
Please include, where possible:
- product or service name
- product version or software version
- description of the vulnerability
- steps to reproduce the issue
- possible impact
- your contact details
We aim to acknowledge receipt of vulnerability reports within 3 working days. We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and, where necessary, provide a mitigation or fix. PhotonFirst shall keep the reporter up to date on the progress of the vulnerability handling.
This channel is intended only for reporting suspected security vulnerabilities.General support requests, commercial questions, and non-security issues should be submitted through the regular contact channels.
Scope. This process covers security vulnerabilities in PhotonFirst products (hardware, firmware, software) and the services we operate for customers. Our corporate website and general IT infrastructure are not in scope; reports about them are received but handled as internal hardening items.
Out of scope. The following are not considered security vulnerabilities and will be closed as informational: missing or non-enforcing DNS/e-mail records (SPF, DKIM, DMARC, DNSSEC, MTA-STS, TLS-RPT, CAA, BIMI); missing HTTP security headers; software version disclosure; clickjacking on pages without sensitive actions; output of automated scanners without a demonstrated exploitable impact; social engineering, physical attacks and denial-of-service testing.
Rewards. PhotonFirst does not operate a bug bounty programme and does not offer financial rewards or public acknowledgement.
Handling. We triage every report. Reports accepted as vulnerabilities receive progress updates until resolution; reports classified as informational or out of scope are closed with a single reply.
Good faith. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us reasonable time to respond.
