Coordinated Vulnerability Disclosure Procedure
Kuori is committed to protecting the security of our products and customers. We encourage security researchers, customers, partners and other stakeholders to responsibly report potential security vulnerabilities to us.
Our Coordinated Vulnerability Disclosure (CVD) procedure enables us to investigate reported vulnerabilities, coordinate remediation and communicate relevant security information.
How to report a vulnerability
If you believe you have identified a security vulnerability in a Kuori product, please provide us with as much relevant information as possible.
A vulnerability report should preferably include:
Description of the vulnerability
Affected product
Affected software or firmware version
Steps to reproduce the vulnerability
Potential impact
Proof-of-concept or supporting information, where available
Contact information for follow-up communication
REPORTING CONTACT
SECURITY EMAIL
[ADD EMAIL]
SUGGESTED SUBJECT
Security Vulnerability Report
Please include as much of the information listed on this page as possible so we can assess the report quickly.
SUBMIT A REPORT
What happens after a report?
01 Kuori acknowledges receipt of the report.
02 The reported vulnerability is assessed and, where appropriate, validated.
03 The potential impact and severity are evaluated.
04 Affected products and versions are identified.
05 An appropriate remediation is developed and validated.
06 Relevant security information is communicated where necessary.
Responsible disclosure
We ask reporters to avoid activities that could compromise customer data, disrupt services or negatively affect the availability or integrity of Kuori products.
If testing is required to demonstrate a vulnerability, please limit testing to the minimum necessary to verify and document the issue.
