Vulnerability Disclosure Policy

← Security
Security

Vulnerability Disclosure Policy

Xertified AB welcomes responsible disclosure of security vulnerabilities in our products, services and infrastructure. This policy describes how to report a vulnerability, what you can expect from us in response, and the boundaries of our disclosure programme.

Reporting

How to report a vulnerability

01

Email us

Send your report to security@xertified.com. If it contains sensitive information, encrypt it with our PGP key.

02

Verify the key

Our PGP key is published at xertified.com/pgp-key.txt.

A491 4B82 777A FC3C 804B FDD0 F6E1 F949 234E 49B2

03

Tell us what you found

Include a description of the vulnerability and its impact, the affected product or system, steps to reproduce, and any proof-of-concept material. More detail means a faster assessment.

Terms

What to expect

Response

Acknowledgment within 5 business days

We keep you informed as we investigate, notify you when the issue is remediated, and give you the opportunity to review our assessment before any public disclosure. Response timelines scale with assessed severity.

Scope

What this policy covers

Vulnerabilities in Xertified products and services — Lock hardware, client software, the XMS management system, and xertified.com web infrastructure.

Excluded

Out of scope

Third-party products we do not control, issues requiring physical access to a device already in an attacker’s possession, and social engineering or phishing directed at our staff.

Privacy

Confidentiality

We will not require identification as a condition of receiving or processing a report. All reports are treated as confidential and your contact details are never shared without your explicit consent.

Rewards

Bug bounty and finder’s fee

We do not operate a formal bug bounty programme. We may, at our discretion, offer recognition or compensation where a disclosure represents significant value and the finder has acted in good faith. Any entity claiming to run a bounty programme on our behalf should be treated as a scam and reported to us.

Testing

Penetration testing

We allow mutually agreed penetration testing and security reviews with third parties, customers, partners and suppliers. Contact us to discuss scope, timing and terms before you begin.

Found something?

We read every submission. If you would like to be credited for your contribution, say so in your report — contributors are listed on our acknowledgments page.

Report a vulnerability See acknowledgments

Policy last reviewed July 2026 · Xertified AB, Vasagatan 12, SE-111 20 Stockholm, Sweden