Vulnerability Disclosure Policy
Introduction
Since security is of critical importance to us and to our customers, we at Claypaky are committed to ensuring the safety and security of our products and services. Claypaky supports coordinated vulnerability disclosure and encourages responsible vulnerability testing, we take any reports of security issues seriously.
To report a potential security issue, please follow the steps described in the “Reporting procedure” section.
Reporting procedure
- Submit the Security Report at security@claypaky.it
- Use our PGP public key (pgp-key.txt) to encrypt any email submissions.
- Write the Security Report in English.
-
Provide sufficient contact information, such as:
- your email;
- name of the person who found the security issue.
- Specify whether you are reporting:
- a potential vulnerability for which exploitation is not suspected, or
- a security incident or suspected active exploitation
- Provide the following information:
- date when the vulnerability or incident has been detected;
- details about how it has been discovered;
- a technical description of the issue.
- Provide as much information as you can on the product or service affected, such as:
- version number (hardware and software);
- configuration of the setup used.
- If you wrote specific proof-of-concept or exploit code of the vulnerability, please provide a copy. Please ensure all submitted code is clearly marked as such and is encrypted with our PGP key.
- If you have identified specific threats related to the root cause of the vulnerability or the incident, assessed the risk, or have seen the vulnerability being exploited in other products, please provide that information.
Internal assessment and action
-
Claypaky will acknowledge receiving your Security Report within 3 business days
- If the Security Report contains all the required information, Claypaky will provide a unique tracking number and a contact person;
- If the Security Report is not complete (more information is needed), Claypaky will request the missing information, and no more action will be taken.
-
Claypaky will start an internal management process to manage the reported security issue:
- Receipt
- Triage
- Verification
- Remediation
- Claypaky will monitor the status of the management process, and you will receive a communication at the end of each stage.
- Claypaky will use existing customer notification processes to manage the release of patches or security fixes, which may include, without limitation and at Claypaky’s sole discretion, direct customer notification or public release of an advisory notification on our website.
- If the vulnerability or incident source is actually in a third-party component or service that is part of our product/service, Claypaky will notify the Security Report to that third party and advise you of that notification. To that end, please inform us in your email whether it is permissible in such cases to provide your contact information to the third party.
Notice
If you share any information with Claypaky in the context of responsible disclosure, you are agreeing that the information you submit will be considered as non-proprietary and non-confidential. Claypaky is allowed to use shared information, or part of it, without any restriction. You agree that submitting information does not create any rights for you or any obligation for Claypaky. Personal data is processed by Claypaky based on the privacy policy.