Purpose
At INVISIO, product security is an important part of how we design, develop, manufacture, release, maintain, and support our products.
The appropriate security measures are applied to all products on a risk-based approach.
Vulnerability disclosure
INVISIO recognizes that products may become vulnerable to new threats over time. We welcome responsible reports from customers, partners, suppliers, and other external parties.
The purpose of this vulnerability disclosure process is to allow potential security weaknesses to be reported, assessed, and addressed before they might be exploited maliciously.
Contact details
If you believe you have found a security vulnerability affecting an INVISIO product, please contact us at:
Security contact: product-security@invisio.com
You can include the following details:
• affected product, model, software, firmware, or service;
• version number or configuration, if known;
• description of the vulnerability;
• steps to reproduce;
• potential impact;
• any supporting screenshots, logs, or technical details.
Upon the receival of the vulnerability report, we will aim to acknowledge the receipt within 7 days and perform an assessment within 14 days. In case more testing and investigation is required, we will perform it in 30 days. The remediation will be prioritized based on risk. After being tested, INVISIO will coordinate the disclosure with the reporter within following 7 days.
Contact details
If you believe you have found a security vulnerability affecting an INVISIO product, please contact us at product-security@invisio.com
Keep reading for more details.