Xertified AB welcomes responsible disclosure of security vulnerabilities in our products, services and infrastructure. This policy describes how to report a vulnerability, what you can expect from us in response, and the boundaries of our disclosure programme.
How to report a vulnerability
Email us
Send your report to security@xertified.com. If it contains sensitive information, encrypt it with our PGP key.
Verify the key
Our PGP key is published at xertified.com/pgp-key.txt.
A491 4B82 777A FC3C 804B FDD0 F6E1 F949 234E 49B2
Tell us what you found
Include a description of the vulnerability and its impact, the affected product or system, steps to reproduce, and any proof-of-concept material. More detail means a faster assessment.
What to expect
Acknowledgment within 5 business days
We keep you informed as we investigate, notify you when the issue is remediated, and give you the opportunity to review our assessment before any public disclosure. Response timelines scale with assessed severity.
What this policy covers
Vulnerabilities in Xertified products and services — Lock hardware, client software, the XMS management system, and xertified.com web infrastructure.
Out of scope
Third-party products we do not control, issues requiring physical access to a device already in an attacker’s possession, and social engineering or phishing directed at our staff.
Confidentiality
We will not require identification as a condition of receiving or processing a report. All reports are treated as confidential and your contact details are never shared without your explicit consent.
Bug bounty and finder’s fee
We do not operate a formal bug bounty programme. We may, at our discretion, offer recognition or compensation where a disclosure represents significant value and the finder has acted in good faith. Any entity claiming to run a bounty programme on our behalf should be treated as a scam and reported to us.
Penetration testing
We allow mutually agreed penetration testing and security reviews with third parties, customers, partners and suppliers. Contact us to discuss scope, timing and terms before you begin.
Found something?
We read every submission. If you would like to be credited for your contribution, say so in your report — contributors are listed on our acknowledgments page.
Report a vulnerability See acknowledgments
Policy last reviewed July 2026 · Xertified AB, Vasagatan 12, SE-111 20 Stockholm, Sweden