Your Quote Request

No products in the enquiry.

Vulnerability Disclosure

Last updated: September 9, 2026

At IN2CORE, we recognize that the security of our products, systems, and services is important; however, vulnerabilities may still occur despite best efforts. If exploited, such vulnerabilities may impact the confidentiality, integrity, or availability of systems and data.

This policy defines how vulnerabilities can be reported, assessed, and addressed to enable timely remediation and reduce risk. It supports compliance with applicable regulations and aligns with recognized standards.

If you believe you have identified a vulnerability in one of our products or services, please report it in accordance with this policy.

Authorisation

IN2CORE will not initiate legal action against you for security testing activities conducted in accordance with this policy, provided such activities are performed in good faith, remain within the defined scope, and comply with applicable laws and regulations.

This statement does not apply to activities that involve malicious intent; unauthorized access beyond what is necessary to demonstrate a vulnerability; data exfiltration; service disruption; harm to IN2CORE or our customers; compromise of the confidentiality, integrity, availability, or safety of our customers’ operations or our services; accessing, modifying, or deleting data belonging to other users; failure to give us a reasonable amount of time to remediate the vulnerability before public disclosure; or any actions that fall outside the scope of this policy.

Scope

This policy applies to security vulnerabilities affecting IN2CORE products with digital elements. This includes hardware, firmware, embedded software, desktop and mobile applications, and any third-party components that are integrated into or distributed as part of our products.

The following are outside the scope of this policy:

  • Third-party products or services that are not integrated into or distributed with our products
  • Third-party products that we only resell, where responsibility for maintenance and security remains with the vendor
  • Services operated entirely by third parties (e.g. external cloud platforms not controlled by us)
  • Customer-managed infrastructure, configurations, or environments
  • Products or components designated as End-of-Support (EoS)
  • Issues affecting unsupported, modified, or tampered products
  • Automated scanner results without validation
  • Theoretical issues without practical exploitability
  • Missing security headers without demonstrated security impact
  • Clickjacking or self-XSS issues that do not present a material security risk

Vulnerabilities affecting third-party products or services outside of IN2CORE’s control should be reported directly to the relevant vendor in accordance with their disclosure policy. If such a report is submitted to us, we may assist in identifying the appropriate vendor and, where appropriate, help coordinate disclosure.

Reports relating to End-of-Support products are welcome; however, remediation, fixes, or updates cannot be guaranteed.

Reporting a Vulnerability

If you believe you have identified a security vulnerability in IN2CORE products or services, please report it to: security@in2core.com

Please do not disclose vulnerabilities through public channels, including customer support, sales contacts, social media, or community forums. To protect sensitive information, please avoid submitting credentials, personal data, or any third-party confidential information in your report.

To support efficient triage and investigation, please include as much of the following information as possible:

  • Affected product name and model number
  • Software/ firmware version
  • Environment details (e.g. operating system, device type, configuration)
  • Description of the vulnerability, type of vulnerability (e.g. XSS, buffer overflow, authentication bypass, etc.) and potential impact
  • If known, whether the vulnerability is actively being exploited
  • Step-by-step instructions to reproduce the issue
  • Any prerequisites or specific conditions required to trigger the vulnerability
  • Proof of Concept (PoC), exploit code, logs, or screenshots if available
  • Date of discovery
  • Your contact information (email address)
  • Optional: your name or alias/handle

Reports should be submitted in English to ensure efficient processing and compliance with applicable regulatory requirements.

Commitment

When you submit a valid vulnerability report, IN2CORE commits to handling it in a structured and timely manner:

  • Acknowledgement of receipt: within 5 business days.
  • Initial assessment: within 7 days.
  • Investigation: we will validate and investigate the report and keep you informed of key findings at least every 14 days until resolution or closure.
  • Confidentiality: reports are treated as confidential and shared only on a need-to-know basis.
  • Public disclosure: where applicable, we will coordinate with you on responsible disclosure timing. If you agree, we may acknowledge your contribution in any public security advisory.
  • EU Cyber Resilience Act (CRA) Compliance: If any reported vulnerability falls within the criteria of an actively exploited vulnerability or a severe incident as defined by the CRA, we will in parallel with internal investigation report it to ENISA and the relevant CSIRT within 24 hours of becoming aware of it.

If you have any questions or require further clarification regarding this policy, please do not hesitate to contact us at : security@in2core.com