Welcome to IRINOX Professional, a business unit of IRINOX S.p.A., a Certified B Corporation™ · irinoxprofessional.com
IRINOX
IRINOX SECURITY · CVD

Coordinated Vulnerability Disclosure Policy (CVD)

This policy explains how to report a potential vulnerability to IRINOX and how its handling should be coordinated before any public disclosure.

BetaDraft copy.

Purpose and scope

This policy applies to potential security vulnerabilities affecting IRINOX products with digital elements and directly connected digital services. The channel is available to researchers, customers, partners and anyone who identifies a possible security issue.

This policy does not constitute authorization to perform testing activities on IRINOX products, systems or infrastructure.

How to submit a report

Use the dedicated form and, where available, provide enough information to reproduce and assess the issue:

  • the affected product, model and software or firmware version;
  • a description of the vulnerability and the steps required to reproduce it;
  • the potential impact and the conditions under which the issue occurs;
  • relevant technical evidence, avoiding personal data or unnecessary information;
  • an email address at which you can receive the reference number and any updates.

Responsible conduct

When researching and reporting an issue, please:

  • limit any verification to the minimum necessary to demonstrate the vulnerability;
  • do not alter, delete, copy or disclose data, and stop if confidential information is encountered;
  • do not compromise availability, security, business continuity or personal safety;
  • do not use social engineering, physical attacks, denial of service, persistence or credential compromise;
  • keep technical details confidential until coordination with IRINOX is complete and comply with applicable law.

Handling and coordinated disclosure

IRINOX registers the report, assigns a reference number and assesses its content, impact and possible mitigation measures. Communications and any requests for additional information are sent to the email address provided in the form.

Any public disclosure is coordinated on a case-by-case basis, taking into account the availability of a fix or mitigation and the protection of users. This policy does not establish fixed remediation times, rewards or a bug bounty programme.

This policy supports the vulnerability handling process required by the Cyber Resilience Act, Regulation (EU) 2024/2847.

Have you identified a potential vulnerability?

Submit the information through the dedicated channel. You will receive a reference number for use in subsequent communications.

Go to the reporting form