Report a security vulnerability

At Tecnosicurezza, we are committed to continuously improving the security of our products and digital solutions. As our portfolio evolves to include connected and digitally enabled solutions, safeguarding our customers against cybersecurity risks is a top priority. Security researchers, customers, and suppliers may report potential vulnerabilities in our products.

This page outlines how to report a vulnerability and what to expect from us throughout the process.

 

For security vulnerabilities affecting Gunnebo’s IT estate, gunnebo.com, or other internet-facing services, please refer to our Coordinated Vulnerability Disclosure (CVD) page and use the reporting process described there.

Scope and responsible disclosure

This process applies primarily to products with digital elements and digital solutions that are supported and maintained by Tecnosicurezza. Submission of a report does not create any contractual relationship, entitlement to compensation, or obligation on our part to implement a specific remediation measure or disclosure approach. We will not pursue legal action solely on the basis of good-faith security research conducted in accordance with these guidelines and applicable law.

How to report a vulnerability

This reporting channel is intended for reporting vulnerabilities affecting products with digital elements and related product security concerns. If you believe you have discovered a security vulnerability in those products, please use the appropriate form below to report potential product security vulnerabilities based on your role. Personal data submitted through a vulnerability report will be processed in accordance with our Privacy Notice.

Report a potential vulnerability in a product, component, service or technology supplied to Tecnosicurezza.

Report a potential vulnerability in a Tecnosicurezza product or related digital service as a customer, researcher, partner or other external party.

Responsible disclosure guidelines

We kindly ask that reporters:

Investigation period
Allow us a reasonable period to investigate and remediate the issue before any public disclosure.

Responsible testing
Avoid exploiting the vulnerability beyond what is necessary to demonstrate it

Data protection
Do not access, modify or delete data belonging to others.

Direct reporting
Contact us directly through the appropriate reporting form.

What happens after you submit a report

We follow coordinated vulnerability disclosure principles. The exact process and timing may vary depending on the nature and complexity of the issue, but it will normally include the following stages:

 

    1. Submission received
      We aim to acknowledge receipt of vulnerability reports within a reasonable timeframe.

    2. Initial assessment
      We review the information and may request further details. Where required, we comply with applicable regulatory reporting obligations

    3. Investigation and action
      We investigate the issue and determine the appropriate remediation or mitigation.

    4. Coordinated communication
      Where relevant, we coordinate remediation and disclosure with the reporter.
  1.  
  1.  

Information submitted through this process may be shared within the Tecnosicurezza business and with relevant service providers, suppliers, regulators or authorities where necessary to investigate, mitigate or comply with applicable legal obligations.

General product security enquiries

For enquiries that are not related to a digital product vulnerability report, please use the general contact page.

Security advisories

Where appropriate, Tecnosicurezza may publish security advisories relating to confirmed vulnerabilities.
Each advisory will include: 

  • Advisory ID and date of publication 

  • CVE identifier(s), where applicable 

  • CVSS severity score
     
  • Affected products and versions 

  • Description of the vulnerability 

  • Recommended remediation or mitigation steps