KINEXON Coordinated Vulnerability Disclosure Policy

Discover how to report security vulnerabilities to KINEXON. Our Coordinated Vulnerability Disclosure Policy outlines the reporting process and response.

Purpose and Scope

KINEXON believes that responsible disclosure of security vulnerabilities makes our products safer for everyone. This Coordinated Vulnerability Disclosure (CVD) Policy describes how we work with security researchers and customers to identify, validate, and remediate security vulnerabilities in KINEXON products and services.

This policy applies to all KINEXON products, services, and digital infrastructure. It does not cover vulnerabilities in third-party components, products or services that KINEXON does not operate, ship, or bundle.

Reporting a Vulnerability

To report a potential security vulnerability, please contact our security team:

Email (preferred): psirt@kinexon.com
Please provide as much detail as possible, including:

  • Product name, version, and platform
  • Description of the vulnerability and its potential impact
  • Step-by-step reproduction instructions
  • Proof of concept (screenshots, code, or video)
  • Whether the issue is already known or being exploited

How We Respond

We treat valid reports in good faith and will:

  • Acknowledge receipt promptly
  • Assess whether the report is a vulnerability in a KINEXON product or service, and its severity, as soon as we reasonably can
  • Keep you informed as the case progresses
  • Tell you when the issue is resolved, or when we have determined that it is not a vulnerability we will act on
  • Release a patch and/or advisory as soon as practicable, given the nature of the issue and the affected products

Coordinated Disclosure

KINEXON asks reporters to coordinate public disclosure. Please do not publish vulnerability details until a patch or advisory is available, or until we have agreed another course of action with you.

While we are coordinating:

  1. We will work to validate, reproduce, and remediate the issue.
  2. We will keep you updated on progress.
  3. We ask that you refrain from publishing until a patch or advisory is available, or until we agree otherwise.

If a vulnerability is being actively exploited, we may disclose earlier and may issue an advisory with or without a complete fix. We will notify you before we publish.

If more time is needed, we will say so and agree next steps with you.

Safe Harbour

KINEXON will not pursue legal or regulatory action against researchers who:

  • Discover and report vulnerabilities in good faith under this policy
  • Avoid intentional harm to users, services, or data beyond what is strictly necessary to demonstrate the issue
  • Do not access, modify, or exfiltrate data beyond what is needed for proof of concept. Stay within these boundaries:
    • No denial-of-service testing
    • No social engineering of KINEXON staff, partners, or customers
    • No testing against production customer data. Use test or staging environments where possible
  • Notify us before disclosing to any third party
  • Comply with applicable law in their jurisdiction

We consider good-faith research conducted under this policy to be authorised and will communicate this to law enforcement if necessary.

Acknowledgment and Recognition

KINEXON recognises the contributions of security researchers who help us improve the security of our products. With your permission, we will:

  • Acknowledge your contribution in the security advisory for the vulnerability

We do not currently offer a bug bounty programme. If that changes, we will update this policy.

All researchers will receive confirmation that their report contributed to a fix, regardless of whether they wish to be publicly credited.

Advisory Publication

When a vulnerability is resolved, KINEXON will publish a security advisory that includes:

  • CVE identifier (where assigned)
  • CVSS 3.1 or 4.0 severity score
  • Affected products and versions
  • Fixed versions
  • Remediation guidance for users
  • Acknowledgment of the reporting researcher (with permission)

For qualifying vulnerabilities, advisories are also published in CSAF 2.0 format for machine-readable consumption.