At Aiwos, we take security seriously. We are committed to maintaining the safety of our systems and we welcome collaboration with security researchers. If you discover a vulnerability, please report it to us via the appropriate contact channels. Below is our policy and how we work.
1. Responsibilities and Communication
- We encourage security researchers to report vulnerabilities through the contact methods provided.
- Please ensure your reports are as detailed as possible, including clear instructions on how we can reproduce the issue.
- Reports will be promptly reviewed, and if the issue is urgent, we will take action within a reasonable timeframe.
2. Vulnerability Handling Process
- When we receive a report, our team will first validate the submission.
- If the vulnerability is confirmed, we will establish a timeline to address the issue.
- We collaborate with researchers to resolve the vulnerability and will notify the public when appropriate.
3. Security Measures
- We implement a range of both visible and invisible security measures, including data encryption, secure communication protocols, and regular system audits in compliance with the ISO standards we follow.
- We encourage researchers to perform regular tests and security audits to help identify new vulnerabilities.
4. Privacy
- We respect user privacy and protect personal data in accordance with applicable privacy laws such as the GDPR.
- All security reports are treated confidentially, though we may acknowledge and credit the researcher unless agreed otherwise.
5. Disclosure Timeline & Publication Policy
We ask that you do not publicly disclose any findings before we have confirmed and addressed the vulnerability. Below is a guideline for public disclosure:
- After confirmation: You may publish your findings only after we have deployed a patch or confirmed that a solution is in progress.
- After resolution: Once the issue is fully resolved, you are free to share details of the vulnerability. We will communicate this clearly to you.
Important: If we have shared a resolution timeline, we ask that you respect it to avoid unnecessary public exposure before a fix is in place.
6. Exclusions
Not all types of vulnerabilities fall under our program. We do not accept reports involving:
- Physical testing (e.g., office access, tailgating).
- Social engineering (e.g., phishing, vishing).
- Low-severity issues easily detected by automated scanners.
- Unreliable Proofs of Concept (e.g., reports lacking a working exploit).
7. Contact
If you have questions about our security policy, do not hesitate to reach out via the designated email address. We aim to respond as quickly as possible, but please allow up to 3 business days for a reply.
