Vulnerability Disclosure Policy
How security researchers can report suspected vulnerabilities in Axisonic systems — and what we commit to in return.
1. Reporting a Vulnerability
If you believe you have found a security vulnerability in an Axisonic system, please report it to security@axisonic.com. Include a description of the issue, the affected system or URL, steps to reproduce, and — where sensitive — avoid including live customer data in the report.
2. What We Ask of Researchers
- report in good faith and avoid exploiting a vulnerability beyond what is needed to demonstrate it;
- do not access, modify, or destroy data you do not own;
- do not conduct denial-of-service or social engineering testing; and
- give us a reasonable period to remediate before public disclosure.
3. Our Commitment
We acknowledge valid reports promptly, keep the reporter informed of progress, remediate confirmed vulnerabilities, and follow our incident response process — including notifiable data breach obligations where personal information is involved. We will not take action against researchers who report in good faith and comply with this policy.