Coordinated Vulnerability Disclosure Procedure 

Kuori is committed to protecting the security of our products and customers. We encourage security researchers, customers, partners and other stakeholders to responsibly report potential security vulnerabilities to us.

Our Coordinated Vulnerability Disclosure (CVD) procedure enables us to investigate reported vulnerabilities, coordinate remediation and communicate relevant security information.

 

How to report a vulnerability


If you believe you have identified a security vulnerability in a Kuori product, please provide us with as much relevant information as possible. 

A vulnerability report should preferably include: 

Description of the vulnerability

Affected product

Affected software or firmware version


Steps to reproduce the vulnerability

Potential impact

Proof-of-concept or supporting information, where available


Contact information for follow-up communication


REPORTING CONTACT

SECURITY EMAIL

[ADD EMAIL]

SUGGESTED SUBJECT

Security Vulnerability Report

Please include as much of the information listed on this page as possible so we can assess the report quickly.

 

 

SUBMIT A REPORT


What happens after a report?


01   Kuori acknowledges receipt of the report. 


02    The reported vulnerability is assessed and, where appropriate, validated. 


03    The potential impact and severity are evaluated. 


04    Affected products and versions are identified. 


05    An appropriate remediation is developed and validated.  


06    Relevant security information is communicated where necessary. 

Responsible disclosure


We ask reporters to avoid activities that could compromise customer data, disrupt services or negatively affect the availability or integrity of Kuori products.

If testing is required to demonstrate a vulnerability, please limit testing to the minimum necessary to verify and document the issue.