Product Security – Vulnerability Management
Product Security – Vulnerability Management
The security of our products and the protection of our customers are Piller’s top priorities. Despite careful development and extensive testing, security vulnerabilities may arise in software, hardware, or cloud services.
We value the support of our customers, security researchers, and the community in identifying and resolving such vulnerabilities. This policy describes how you can securely report potential vulnerabilities to our Product Security Incident Response Team (PSIRT) and how we handle these reports.
What You Can Report
Please report to us any potential vulnerabilities or security risks you discover in our products, services, or the associated infrastructure. These include, in particular:
- Security vulnerabilities in the firmware or software of our products
- Opportunities for unauthorized data manipulation or data leakage
- Misconfigurations that compromise product security
Note: This policy does not apply to general support requests, contractual IT issues, or error messages that are not security-related.
How to Submit a Report
To report a vulnerability, please send an email to our PSIRT:
- Email address: [email protected]
- Encryption: To protect sensitive data, please encrypt your message using our PGP key.
- PGP Key ID: 4553D9CFDB15D239
- PGP fingerprint: 1FB681C280372CCBEF95A4CF4553D9CFDB15D239
- Public PGP key
Please include the following information in your report
- Name of the affected product and the exact software/firmware version
- A detailed description of the vulnerability
- Step-by-step instructions or a proof-of-concept (PoC) for reproducing the vulnerability
- Potential impacts of the vulnerability (e.g., remote code execution, denial of service)
- Your contact information in case of follow-up questions (and whether you would like to be named in the subsequent disclosure)
Thank you very much for helping to ensure the safety of our products!
Our Process After a Vulnerability Is Reported
Once we receive your report, our standardized PSIRT process begins:
We will confirm receipt of your report within 3 business days.
Our experts review and assess the vulnerability (using the CVSS scoring system). If necessary, we will contact you with any questions.
We will promptly develop a security update, a patch, or a workaround to resolve the risk.
If the vulnerability is already being actively exploited, our PSIRT will simultaneously initiate the legally required reports to the authorities (within the 24/72-hour deadline).
We notify affected customers about the update. If you wish, we will list you by name in our security advisories as the discoverer (acknowledgment).
Rules of Conduct for Those Who Discover Security Vulnerabilities
We expect you to adhere to the following code of conduct when conducting your analysis. In the event of a violation, we will be forced to take legal action against you.
Do not conduct any tests that interfere with the operation of our products, delete data, or compromise the security of our customers (e.g., brute-force or DDoS attacks).
Do not access data that does not belong to you. If you gain access to sensitive data, stop the test and report the incident immediately.
Do not disclose any information about the vulnerability to third parties until we have analysed and resolved the issue together (as part of a coordinated response).