Vulnerability and Incident Disclosure Policy
Revision 00 of September 10th, 2026
1. Introduction
Since security is of fundamental importance to us and to our customers, SISGEO undertakes to ensure the security of its products and services.
SISGEO promotes the coordinated disclosure of vulnerabilities (Coordinated Vulnerability Disclosure) and encourages the responsible performance of security verification activities. Every report concerning potential vulnerabilities or security incidents is taken seriously.
To report a potential security issue, follow the instructions provided in the “Reporting Procedure” section.
2. Reporting procedure
To report a potential security vulnerability or security incident:
- Submit the Security Report through the SISGEO Product Security web form available at Security Reporting – Sisgeo.
- Write the Security Report in English.
- Provide sufficient contact information, including:
- your email address;
- the name of the person who identified the security issue.
- Provide the following information:
- the date on which the vulnerability or incident was detected;
- details of how the vulnerability or incident was discovered;
- a technical description of the issue.
- Provide as much information as possible about the affected product or service, including:
- product name and model;
- serial number (also mac address, devEUI, ect.), where applicable;
- hardware, firmware and software version numbers;
- the configuration of the setup used;
- any connected systems, components or services relevant to the issue.
- If you have developed specific proof-of-concept or exploit code, indicate this in the Security Report. Place any executable file, script or active content in a ZIP archive and do not submit it as a directly executable attachment.
- If you have identified specific threats associated with the root cause of the vulnerability or incident, assessed the related risk, or observed the same vulnerability being exploited in other products, please provide this information.
Please do not include unnecessary personal data or information unrelated to the reported security issue.
3. Internal assessment and action
- SISGEO will acknowledge receipt of the Security Report within five business days.
- If the Security Report contains sufficient information, SISGEO will confirm that the report has been registered and provide a case reference for subsequent communications.
- If additional information is required, SISGEO will contact the reporter and request the missing information. The assessment may be suspended until sufficient information has been received.
- SISGEO will initiate its internal product security management process, which includes the following stages:
- Receipt and registration;
- Triage and technical verification;
- Decision and remediation;
- Communication, release and closure;
- Regulatory notification, where applicable.
- SISGEO will provide the reporter with appropriate updates at significant milestones, normally following technical verification and at closure or upon release of a corrective measure, where applicable and provided that sufficient contact information has been supplied.
- After becoming aware of an actively exploited vulnerability or a severe incident affecting the security of a product, SISGEO, where required by applicable law, will inform impacted users without undue delay and, where appropriate, all relevant users, of the event and of the corrective or mitigating measures they can apply.
SISGEO will use its established customer-notification processes, which may include:
- publication of a Security Advisories – Sisgeo on the SISGEO website;
- direct notification to affected customers;
- release of a software or firmware update;
- provision of temporary risk-reduction or mitigation measures.
- If SISGEO determines that the vulnerability or incident originates from a third-party component or service incorporated into, or used in connection with, a SISGEO product or service, SISGEO may notify the relevant third party and inform the reporter that the notification has been made.
Please indicate in the Security Reporting – Sisgeo whether SISGEO is authorised to share your name and contact information with the relevant third party. If consent is not provided, SISGEO may still share the technical information necessary to investigate and manage the issue, without disclosing the reporter’s identity or contact details.
4. Notice
By sharing information with SISGEO in the context of responsible vulnerability disclosure, you acknowledge that the submitted information will be treated as non-proprietary.
Unless otherwise agreed in writing, SISGEO may use, reproduce, analyse, modify and share the submitted technical information, in whole or in part, for the purposes of investigating, managing and resolving the reported security issue and fulfilling any applicable legal or regulatory obligations.
Submitting a Security Report does not grant the reporter any rights over SISGEO products, services or systems and does not create any contractual, financial or other obligation for SISGEO.
SISGEO does not currently operate a bug bounty programme and does not undertake to provide financial compensation or other rewards for submitted reports.
Personal data provided in connection with a Security Report will be processed by SISGEO in accordance with the SISGEO Privacy Policy, available at Privacy Policy – Sisgeo.