SECURITY POLICY

Smartoptics’ policy for Coordinated Vulnerability Disclosure

Smartoptics is committed to rapidly addressing cyber-security vulnerabilities affecting our products by providing clear information, such as about the impact, severity and its mitigation.

Smartoptics is also committed to following the legal regulations under CRA to report actively exploited vulnerabilities to the EU Single Reporting Platform according to the mandated timelines.

Reporting vulnerabilities to Smartoptics

All vulnerabilities are to be reported to the contacts specified in: https://smartoptics.com/.well-known/security.txt

Vulnerability handling process

All vulnerabilities reported to Smartoptics are handled according to the following policy:

1. Intake and triage

Smartoptics receives vulnerability reports via the contacts listed in the security.txt file and may contact the reporter for more details.

The security team will work together with the product teams to evaluate, reproduce and understand the potential impact of the reported vulnerability.

If the reported vulnerability is not found to be affecting Smartoptics products, then this information is reported back to the reporter and the case is closed.

The goal is to provide an initial response within 5 business days. The anonymity of the reporter is protected during the entire process.

If the reported vulnerability is indeed found to be affecting Smartoptics products then the next steps are executed.

2. Mitigate

Smartoptics analyzes the severity of the reported vulnerabilities using metrics such as the CVSS and EPSS, as well as evaluates the risks associated with the reported vulnerability in the specific product.

Smartoptics also evaluates and documents the mitigation-mechanisms for the reported vulnerability, and simultaneously an execution is planned according to our ISO 27001 compliant development process.

3. Disclose

Smartoptics is required by law to be compliant to the EU Cyber Resilience Act (CRA). Consequently, all actively exploited vulnerabilities reported to Smartoptics shall be disclosed to the EU Single Reporting Platform (SRP) within 24 hours of awareness of such a vulnerability at Smartoptics. A follow-up report shall be filed to the SRP within 72 hours. A final report shall be produced according to the CRA reporting rules no later than 14 days after a fix is ready.

Quoting the CRA: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847

‘actively exploited vulnerability’ means a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner;

All other reported vulnerabilities (that are not actively exploited) shall be disclosed primarily in two forms depending on the severity of the vulnerability:

  1. Confidential disclosure to affected parties
    All the affected parties will be informed at appropriate times during the mitigation process.
  2. Public disclosure
    Smartoptics will produce a public vulnerability disclosure in the form of a security advisory once it has been concluded to be safe to do so.

The privacy of the reporter is guaranteed and all communication with the reporter shall be treated accordingly.

Contact us

If you have any questions related to security, or if you want to report a security incident or vulnerability, use the contact details provided below. 

Email: security(at)smartoptics.com