We believe that vulnerability disclosure increases overall safety and security and builds customer trust in our products and services. We welcome disclosures and collaboration with security researchers and reporters. We are committed to addressing reported security vulnerabilities via a coordinated and streamlined approach designed to protect our customers.
This policy aims to provide information on how we handle reported security vulnerabilities found on our products and services, including responsibility, communication, report contents, scope, timeline, and security advisory.
We commit to:
Security researchers or reporters shall not:
We request security researchers and reporters to report any potential security vulnerabilities to the Product Security Vulnerability Response Team via the email address aaesproduct.security@assaabloy.com.
We encourage security researchers and reporters to encrypt email communication with (Pretty Good Privacy) PGP encryption software using our public key
We expect security researchers and reporters to provide the following information (via email) when reporting a potential security vulnerability:
Security researchers or reporters can report a security vulnerability found in any of the following products:
We will respond within 24 hours of receiving a security vulnerability report from security researchers or reporters. We will communicate regularly with security researchers or reporters until the resolution of the security vulnerability.
We expect to remediate a reported and valid vulnerability within 90 days of receiving the report, depending on the complexity, the number of products affected, and the severity.
We will issue a security advisory on our website once a fix becomes available for the reported vulnerability.