Product security vulnerability disclosure policy
1. Purpose and scope
Vikinor is committed to supporting the security, reliability, and long-term performance of its products.
This policy sets out the process for reporting suspected cybersecurity vulnerabilities affecting Vikinor products and Vikinor’s approach to handling such reports. It applies to relevant Vikinor products currently in use, under evaluation, or supplied as part of a wider customer project or infrastructure solution.
Reports may be submitted by customers, business partners, system integrators, installation and service partners, suppliers, security researchers, CERTs/CSIRTs, industry bodies, and other parties with relevant information concerning a potential cybersecurity vulnerability affecting a Vikinor product.
The scope includes products or systems containing digital elements, including:
- controllers;
- firmware and embedded software;
- sensors;
- communication interfaces;
- monitoring functions; and
- remote access or remote management capabilities.
2. What should be reported
This reporting channel is intended for suspected cybersecurity vulnerabilities or security weaknesses affecting Vikinor products.
Examples include:
- unauthorized or unintended access to a product, controller, or management function;
- vulnerabilities in firmware, embedded software, or communication interfaces;
- weaknesses in authentication, access control, or security configuration;
- vulnerabilities affecting monitoring or remote management functions;
- cybersecurity weaknesses that could affect the availability, integrity, confidentiality, or safe operation of a product; and
- suspected active exploitation of a cybersecurity vulnerability affecting a Vikinor product.
A reported issue does not need to be a confirmed vulnerability at the time of reporting. Vikinor will assess the information provided to determine whether the issue represents a cybersecurity vulnerability and whether further action is required.
This reporting channel is not intended for general product support, warranty claims, spare parts requests, installation questions, delivery matters, commercial enquiries, or ordinary product quality issues. Such matters should be directed to the relevant Vikinor contact or support channel.
3. How to report a vulnerability
Suspected product cybersecurity vulnerabilities should be reported through Vikinor’s designated Product Security Vulnerability Reporting channel. Reporters should preferably use the reporting form provided on Vikinor’s website, which helps collect the information needed to review and assess the report efficiently.
Alternatively, reports may be submitted through Vikinor’s designated product security email address, particularly where the report contains sensitive technical information:
[Insert dedicated product security email address]
Vikinor may request additional information where needed to understand, reproduce, assess, or respond to the reported issue.
4. Responsible disclosure expectations
Reporters are expected to act responsibly, in good faith, and in accordance with applicable law when identifying and reporting potential vulnerabilities. Testing should not cause harm or disruption, compromise privacy or safety, or go beyond what is reasonably necessary to identify and demonstrate the suspected vulnerability.
Vulnerability details should be kept confidential until Vikinor has had a reasonable opportunity to investigate and, where appropriate, address the issue. Any intended public disclosure should be coordinated with Vikinor.
Vikinor does not intend to pursue legal action against individuals or organizations that identify and report potential vulnerabilities in good faith and comply with this policy. Reports are submitted voluntarily, and Vikinor does not offer compensation, rewards, or other financial incentives for vulnerability reports.
5. Vikinor’s response
Vikinor will review reported vulnerabilities and assess their validity, severity, potential impact, and relevance to Vikinor products.
Vikinor will acknowledge receipt of a vulnerability report within 2 business days and will request additional information where needed to support the assessment.
Relevant internal functions, suppliers, or technology partners will be involved as appropriate, and Vikinor will determine and coordinate the necessary mitigation, corrective action, customer communication, security update, configuration guidance, or other follow-up.
The timing and nature of any resulting communication or corrective action will depend on the vulnerability’s nature, complexity, severity, potential impact, available mitigation, relevant third-party coordination, and applicable legal or regulatory requirements.
6. Confidentiality and information handling
Information submitted under this policy will be used to assess, investigate, and respond to the reported vulnerability.
Vikinor may share relevant information internally and, where necessary, with suppliers, technology partners, customers, advisors, authorities, or other parties involved in investigating or addressing the issue.
Submitted information will be handled in accordance with applicable confidentiality, data protection, and information security requirements.