Vulnerability disclosure

iGrid S.L. responsible disclosure statement

Since secu­ri­ty is of crit­i­cal impor­tance to us and to our cus­tomers, we at iGrid S.L. are com­mit­ted to ensur­ing the safe­ty and secu­ri­ty of our prod­ucts and ser­vices. iGrid S.L. sup­ports coor­di­nat­ed vul­ner­a­bil­i­ty dis­clo­sure and encour­ages respon­si­ble vul­ner­a­bil­i­ty test­ing, we take any reports of poten­tial secu­ri­ty vul­ner­a­bil­i­ties seriously.

Please fol­low these steps to report a poten­tial secu­ri­ty vulnerability:

 

Report­ing Procedure:

1. Please use our PGP pub­lic key to encrypt any email sub­mis­sions to us at [email protected]

2. Pro­vide your reference/advisory num­ber and suf­fi­cient con­tact infor­ma­tion, such as:

2.1. Your con­tact infor­ma­tion
2.2. Name of the per­son who found the vul­ner­a­bil­i­ty
2.3. Date when the vul­ner­a­bil­i­ty was detect­ed and details about how it was discovered

3. Include a tech­ni­cal descrip­tion of the con­cern or vul­ner­a­bil­i­ty. Pro­vide as much infor­ma­tion you can on the prod­uct or ser­vice, like ver­sion num­ber, and con­fig­u­ra­tion of the set­up used (i.e. tools). If you wrote spe­cif­ic proof-of-con­cept or exploit code, please pro­vide a copy. Please ensure all sub­mit­ted code is clear­ly marked as such and is encrypt­ed with our PGP key.

4. If you have iden­ti­fied spe­cif­ic threats relat­ed to the vul­ner­a­bil­i­ty, assessed the risk, or have seen the vul­ner­a­bil­i­ty being exploit­ed, please pro­vide that infor­ma­tion.

 

Secu­ri­ty Vul­ner­a­bil­i­ty Report Assess­ment and Action:

1. iGrid S.L. will:

1.1. acknowl­edge receiv­ing your report with­in 7 busi­ness days.
1.2. pro­vide you with a unique track­ing num­ber for your report.
1.3. assign a con­tact per­son to each sub­mit­ted case.
1.4. noti­fy the inter­est­ed inter­nal tech­ni­cal teams.

2. iGrid S.L. will keep you informed on the sta­tus of your report.

3. If the vul­ner­a­bil­i­ty is actu­al­ly in a third-par­ty com­po­nent or ser­vice which is part of our product/service, we will refer the report to that third par­ty and advise you of that noti­fi­ca­tion. To that end, please inform us in your email whether it is per­mis­si­ble in such cas­es to pro­vide your con­tact infor­ma­tion to the third party.

4. Upon receiv­ing a vul­ner­a­bil­i­ty report, iGrid S.L. will:

4.1. Ver­i­fy the report­ed vul­ner­a­bil­i­ty.
4.2. Work on a res­o­lu­tion.
4.3. Per­form QA/validation test­ing on the res­o­lu­tion.
4.4. Release the res­o­lu­tion.
4.5. Share lessons learned with devel­op­ment teams.

5. iGrid S.L. will use exist­ing cus­tomer noti­fi­ca­tion process­es to man­age the release of patch­es or secu­ri­ty fix­es, which may include with­out lim­i­ta­tion and at iGrid S.L. sole dis­cre­tion direct cus­tomer noti­fi­ca­tion or pub­lic release of an advi­so­ry noti­fi­ca­tion on our website.

 

Impor­tant:

1. Refrain from includ­ing sen­si­tive per­son­al infor­ma­tion in any screen shots or oth­er attach­ments you pro­vide to us.

2. Do not per­form any vul­ner­a­bil­i­ty test­ing on appli­ca­tions, prod­ucts or ser­vices that are active­ly in use. Vul­ner­a­bil­i­ty test­ing should only be per­formed on devices or appli­ca­tions, prod­ucts or ser­vices not cur­rent­ly in use or not intend­ed for use.

3. For web based appli­ca­tions, prod­ucts or ser­vices, please use demo/test envi­ron­ments to per­form vul­ner­a­bil­i­ty testing.

4. Do not take advan­tage of the vul­ner­a­bil­i­ty or prob­lem you have dis­cov­ered; for exam­ple, by down­load­ing more data than nec­es­sary to demon­strate the vul­ner­a­bil­i­ty or delet­ing or mod­i­fy­ing any data. Try to not to delete or use data belong­ing to oth­er users.

5. As part of respon­si­ble co-ordi­na­tion of vul­ner­a­bil­i­ty dis­clo­sure, we encour­age you to work with iGrid S.L. on select­ing pub­lic release dates for infor­ma­tion on dis­cov­ered vulnerabilities.

6. In the effort to find vul­ner­a­bil­i­ties, actions must not be dis­pro­por­tion­ate, such as, includ­ing with­out limitation:

6.1. Using social engi­neer­ing to gain access or infor­ma­tion.
6.2.Installing or build­ing back­doors in an infor­ma­tion appli­ca­tion, prod­uct or ser­vice with the inten­tion of then using it to demon­strate the vul­ner­a­bil­i­ty.
6.3.Uti­liz­ing a vul­ner­a­bil­i­ty fur­ther than what is nec­es­sary to estab­lish its exis­tence.
6.4.Mak­ing changes to the appli­ca­tion, prod­uct or ser­vice.
6.5.Repeat­ed­ly gain­ing access to the appli­ca­tion, prod­uct or ser­vice or shar­ing access with oth­ers.
6.6.Using brute force attacks to gain access to the appli­ca­tion, prod­uct or ser­vice. This is not a vul­ner­a­bil­i­ty in the strict sense, but rather repeat­ed­ly try­ing out passwords.

7. iGrid S.L. will pro­vide full cred­it to researchers who make a vul­ner­a­bil­i­ty report or per­form test­ing, in pub­licly released patch or secu­ri­ty fix release infor­ma­tion, if requested.

Notice:

If you share any infor­ma­tion with iGrid S.L. in the con­text of respon­si­ble dis­clo­sure, you are agree­ing that the infor­ma­tion you sub­mit will be con­sid­ered as non-pro­pri­etary and non-con­fi­den­tial. iGrid S.L. is allowed to use shared infor­ma­tion, or part of it, with­out any restric­tion. You agree that sub­mit­ting infor­ma­tion does not cre­ate any rights for you or any oblig­a­tion for iGrid S.L.

 

Last update: 

1 Novem­ber 2024