Report a vulnerability

Optimalog designs, develops and integrates software and systems for industrial use and scientific. The security of these systems is a condition of the trust of our customers.

If you have identified a security vulnerability affecting l’one of our products, l’one of our services or our website, we encourage you to notify us. Any report in good faith is welcome, that’it emanates d’client,’a user’a partner or d’a security researcher.

Contact us

So that we can process your report effectively, thank you’specify as much as possible of the product or service in question and its version, a description of the vulnerability, the steps to reproduce, l’impact than you believe, and your contact information. The reports are accepted in French and in English.

What we commit to do

StepTime
Acknowledgement of receipt of your report2 business days
Qualification of the vulnerability and assessment of its severity10 working days
Progress report leading up to the resolutionat least monthly
Correctiondepending on the criticality ; priority critical vulnerabilities
Information of the clients concerned and availability of the patchas soon as the correction

We are committed to addressing all reports made in good faith, keeping you informed of their progress, and not taking any legal action against anyone who reports a vulnerability in accordance with these guidelines.

Unless otherwise requested by your hand, you will be able to be mentioned in the acknowledgements accompanying the publication of the fix.

What we ask of you

  • we report the vulnerability as soon as possible after its discovery ;
  • do not use it beyond what is necessary to demonstrate its existence;
  • not to access, modify, delete or disclose data belonging to third parties ;
  • not to impair the availability of our services or compromise the integrity of our systems;
  • Do not publicly disclose the vulnerability until a fix is available, or until ninety days have passed since the report was submitted, unless otherwise agreed upon by both parties.

Perimeter

These provisions cover the software developed and distributed by Optimalog, the systems that we integrate and deliver — including hardware and software components that make it up — as well as our website.

A vulnerability affecting a third-party component integrated into one of our systems also falls within this scope: in such cases, we coordinate with the relevant vendor and inform our customers of the applicable measures.

Privacy

The information you provide to us is treated confidentially. It is shared only with those whose involvement is necessary to resolve the issue, as well as with affected customers when their information is required to enable them to protect themselves.