Coordinated vulnerability disclosure
Last updated 21st September 2026
We are committed to ensuring the security of operators and customers who use our products and services. The Coordinated Vulnerability Disclosure process of Genexis enables security researchers and customers to have a primary point of contact with a team of product experts. This team coordinates Genexis’ response to disclosed vulnerabilities.
We encourage vulnerability testing by security researchers and by customers, with coordinated reporting to Genexis.
Scope
In scope
- Genexis products that are within their published security support period, including their firmware and their management interfaces.
- The Genexis website (genexis.eu) and the Genexis customer portal (portal.genexis.eu).
Out of scope
- Deployments, configurations, services and networks that are operated by our customers rather than by Genexis. Where a report concerns an operator’s deployment rather than our product, we will tell you so and, where we are able, help you identify the right party to contact.
We ask that a report demonstrates an actual security impact on an in-scope target. Unverified output from automated scanning tools, and reports of missing hardening measures or configuration settings without a demonstrated exploitable condition, are generally not actionable and may be closed without detailed analysis.
Testing guidelines
When testing, please:
- Test only on devices, accounts and systems that are your own or that you have explicit permission to test;
- Stop at the point where you have established that a vulnerability exists, and do not access, modify or delete data belonging to others;
- Do not degrade or interrupt service, including through denial-of-service testing or high-volume or brute-force traffic;
- Do not use social engineering or phishing directed at Genexis employees, our customers or end users, and do not attempt physical access to our premises;
- Do not install malware, backdoors or persistent changes on any system, and remove any test artefacts you create;
- Keep the details of your finding confidential until we have agreed a moment of disclosure with you.
Reporting procedure
Fill in the contact form below. Please provide the following information in your submission:
- Contact information, preferably including organization and contact name, so that we can get in touch with you.
- A description of the vulnerability, including identification of the product, the technical context in which the vulnerability occurred, network configuration details, involved URLs, and any other relevant detail. Please keep this initial submission at a level of detail you are comfortable sending over a web form; we will arrange an encrypted channel with you for the full technical detail.
- Before sharing proof-of-concept exploit scripts, or if you have identified specific threats related to the vulnerability, please first arrange a secure transfer with us.
- Information about other parties you informed, like vulnerability coordinators such as CERTs, NCSC, or similar.
Please avoid including privacy-sensitive information in your submission whenever possible.
To minimize security risks, we request that you coordinate with us on synchronizing the release of information to the public and inform us in advance of your disclosure plans. Please note that depending on the complexity of the reported vulnerability, the full process can take several months.
What you can expect from us
- For reports that are in scope, we will acknowledge receipt within 7 days, verify the reported vulnerability, and formulate a response, which may include developing a solution that will be announced and released through our existing customer notification processes.
- We will inform you of the status of your report and, if requested, mention the vulnerability submitter in the patch notes of the security fix, if any.
- We will treat your report as confidential and will not share your identity with third parties without your agreement, other than where we are required to do so by law.
- If the reported vulnerability involves a supplier component part of our software bill-of-materials, we may refer the report to the component supplier. In this case, we will forward your submission, and the supplier may contact you directly.
- Where the law requires us to notify a national CSIRT, a regulator or another authority about a vulnerability, we will do so, and we will tell you that we have done so.
- If you have made a good-faith effort to follow this policy, we will not initiate or support legal or law-enforcement action against you in connection with your research, and we will consider your activity to be authorized. If a third party brings action against you in relation to research conducted in accordance with this policy, we will make it known that your activity was conducted in compliance with it.
Good faith means, among other things, that you have stayed within the scope and the testing guidelines set out above, and that you have given us a reasonable opportunity to resolve the issue before disclosing it. This policy does not authorize activity that is unlawful for reasons unconnected with the security research itself, and it cannot bind parties other than Genexis.
Terms
By submitting information to us, you grant Genexis the right to use that information without restriction for the purposes of investigating and remediating the vulnerability and improving the security of our products and services. This policy is not an offer of a bug bounty or other reward, and taking part in it does not create a contractual relationship between you and Genexis. Nothing in this paragraph limits the commitments set out above.