If you believe you have found a security vulnerability in a SECO hardware, firmware or software product, please report it to [email protected].

To help us assess and address the issue as quickly as possible, please include, where available:

  • the affected product and version;
  • a description of the vulnerability and its potential impact;
  • the required configuration or prerequisites;
  • the steps to reproduce the issue;
  • any proof-of-concept material, screenshots or relevant logs.

Please report in English or Italian.

This channel is intended for vulnerabilities affecting SECO products and associated software. For privacy matters, commercial support or general IT assistance, please use the relevant SECO contact channels.

After you submit a report, SECO will:

  • acknowledge receipt of your report;
  • assess and, where possible, reproduce the issue, coordinating internally with the relevant product security stakeholders;
  • keep you informed of the progress of our assessment;
  • work towards an appropriate remediation and coordinate the timing of any public disclosure with you.

We ask that you give us a reasonable amount of time to investigate and remediate an issue before disclosing it publicly or to any third party.

We aim to acknowledge your report within 5 business days and to complete an initial triage within 10 business days. To help us focus on remediation, please limit status requests to no more than once every 14 days.

When investigating a vulnerability, please:

Do:

  • act in good faith and comply with all applicable laws and regulations;
  • only test against products or systems that you own or are authorized to test;
  • use non-destructive, proof-of-concept steps, and stop as soon as the issue is demonstrated;
  • protect any personal or confidential data you may encounter, and do not store it longer than necessary.

Do not:

  • access, modify, delete or exfiltrate data that does not belong to you, or access more data than is necessary to demonstrate the issue;
  • perform denial-of-service testing, destructive testing, social engineering, phishing or physical attacks;
  • disclose the vulnerability publicly or to third parties before SECO has had a reasonable opportunity to respond;
  • demand payment or any other compensation in exchange for a report.

SECO welcomes security research carried out in good faith and in line with this policy. If you follow it, we will work with you to resolve the issue and will not pursue legal action against you. Please always act lawfully and respect the privacy and rights of others.

If you have any questions about this policy or about product security at SECO, please get in touch with us at [email protected]