Discover how to report security vulnerabilities to KINEXON. Our Coordinated Vulnerability Disclosure Policy outlines the reporting process and response.
KINEXON believes that responsible disclosure of security vulnerabilities makes our products safer for everyone. This Coordinated Vulnerability Disclosure (CVD) Policy describes how we work with security researchers and customers to identify, validate, and remediate security vulnerabilities in KINEXON products and services.
This policy applies to all KINEXON products, services, and digital infrastructure. It does not cover vulnerabilities in third-party components, products or services that KINEXON does not operate, ship, or bundle.
To report a potential security vulnerability, please contact our security team:
Email (preferred): psirt@kinexon.com
Please provide as much detail as possible, including:
We treat valid reports in good faith and will:
KINEXON asks reporters to coordinate public disclosure. Please do not publish vulnerability details until a patch or advisory is available, or until we have agreed another course of action with you.
While we are coordinating:
If a vulnerability is being actively exploited, we may disclose earlier and may issue an advisory with or without a complete fix. We will notify you before we publish.
If more time is needed, we will say so and agree next steps with you.
KINEXON will not pursue legal or regulatory action against researchers who:
We consider good-faith research conducted under this policy to be authorised and will communicate this to law enforcement if necessary.
KINEXON recognises the contributions of security researchers who help us improve the security of our products. With your permission, we will:
We do not currently offer a bug bounty programme. If that changes, we will update this policy.
All researchers will receive confirmation that their report contributed to a fix, regardless of whether they wish to be publicly credited.
When a vulnerability is resolved, KINEXON will publish a security advisory that includes:
For qualifying vulnerabilities, advisories are also published in CSAF 2.0 format for machine-readable consumption.