Security
We attach great importance to product safety issues. If you discover potential security vulnerabilities in Cergen products, please follow the following process to report to us and we will work together with you to address them.
How to report
Email security@cergen.com
This is our single channel for product security matters.
We acknowledge within 5 business days
and tell you who is handling your report.
We analyse and fix
with a progress update at least every 30 days.
We disclose and credit you
in a security advisory, with your consent.
Please include
- Product model and firmware version
- A description of the vulnerability and its potential impact
- Steps to reproduce, required confiquration or tools
- How to contact you, and whether you wish to be credited
Please do not attach executables. Test only on devices you own or are authorised to test.
Our commitments
business days to acknowledge
days between progress updates, at most
day coordinated disclosure window
security updates during the support period
Fullterms are in our Coordinated Vulnerability Disclosure Policy.We wil not pursue legal action against anyone who reports in good faith and in accordance with that policy.