Coordinated Vulnerability Disclosure Policy

Erlab is committed to handling security vulnerability reports responsibly, promptly and transparently. This policy describes how vulnerabilities can be reported to us, the conduct expected from security researchers, and how Erlab handles the information received.

1. Purpose

This policy applies to the reporting of security vulnerabilities affecting products, services, websites and systems operated by Erlab.

2. Scope

This policy applies to security vulnerabilities affecting products with digital elements, software, firmware, online services, websites and systems operated by Erlab.

This includes, in particular:

  • products and software marketed or maintained by Erlab;

Third-party systems, products or services are not covered by this policy unless they are explicitly identified as being operated by Erlab.

If you are unsure whether something is within scope, or before carrying out any testing that could affect a service, please contact us at securitycra@erlab.net to obtain prior authorization.

3. How to Report a Vulnerability

If you believe you have identified a security vulnerability affecting an Erlab product or service, you can contact us at: securitycra@erlab.net

You can also use the reporting form available on our Cybersecurity page.

You may report a vulnerability anonymously, including through a competent CSIRT.

4. Information to Include

To help us assess your report under the best possible conditions, please provide as much information as possible:

  • the product or service concerned;
  • a clear description of the vulnerability;
  • the steps required to reproduce the issue;
  • the potential impact identified;
  • screenshots, logs, files or proof-of-concept material, where available;
  • your contact details if you wish to be contacted.

Do not provide personal data, confidential information or real secrets unless strictly necessary. Please redact or mask sensitive data in any evidence you provide. If transmitting sensitive information is essential, contact us first so that we can agree on a secure transmission channel.

5. Responsible Security Research Rules

We ask security researchers to:

  • act in good faith;
  • limit testing to what is strictly necessary to demonstrate the vulnerability;
  • not access, modify, delete or exfiltrate data beyond what is strictly necessary to demonstrate the issue;
  • not disrupt the operation of our products, services or infrastructure;
  • not publicly disclose a vulnerability before coordinating with Erlab.

6. Prohibited Activities

The following activities are not permitted:

  • denial-of-service attacks;
  • the exploitation or exfiltration of real data;
  • the modification or deletion of data;
  • establishing persistence within systems;
  • the use of destructive tools or techniques;
  • any activity intended to compromise users, customers, partners or third parties.

7. Our Commitments

For each report received, Erlab aims to:

  • acknowledge receipt of the report within a target period of 5 business days;
  • perform an initial assessment and provide an initial response within a target period of 10 business days;
  • maintain regular communication with the reporter during analysis and remediation, at least every 30 days, when contact details are available;
  • analyze the vulnerability, assess its impact, and define an appropriate corrective or mitigation action;
  • coordinate the disclosure of technical information with the reporter;
  • publish appropriate security information for users when a fix or mitigation measure is available;
  • handle the information and data received confidentially and in accordance with applicable regulations.

The timeframes above are processing targets. They may vary depending on the severity of the vulnerability, technical complexity, the availability of a fix, and the level of risk to users.

Where public disclosure is being considered, Erlab and the reporter will, where possible, agree on a coordinated disclosure timeline. An indicative period of 90 days may be used as a reference, subject to the severity of the vulnerability and whether active exploitation exists.

8. Good-Faith Research

Any security research carried out in good faith and in accordance with this policy will be considered a responsible effort to improve the security of Erlab products and services.

9. Coordinated Disclosure

We ask that no information regarding a vulnerability be made public before coordination with Erlab.

This approach allows sufficient time to analyze the vulnerability, implement appropriate corrective measures, and limit risks to our customers, users and partners.

10. Contact

To report a vulnerability or ask a question regarding this policy, please contact: securitycra@erlab.net

You can also use the reporting form available on our Cybersecurity page.