Security Vulnerability Disclosure Policy

Last updated 10-09-2026

Last updated: 10 September, 2026

Classification: Public

Vioside takes the security of our products seriously. If you believe you've found a security vulnerability, or have evidence that a vulnerability is being actively exploited, we want to hear from you.

This page is an interim disclosure page. A fuller coordinated vulnerability disclosure policy, including formal safe-harbour terms, is planned ahead of December 2027.

How to report

Contact: [email protected]

PGP key: Download

Fingerprint: BD97 339C FE40 6E44 E346 C747 C45D CBCC F1BF 300F

Languages: English

Reporting sensitive vulnerabilities

If your report includes details of an unpatched or actively exploited vulnerability, please encrypt it using our PGP key before emailing it to us:

  1. Download our public key from the link above, or fetch it from keys.openpgp.org by searching the fingerprint.
  2. Verify the fingerprint matches the one published on this page before trusting the key — don't rely solely on a key found elsewhere.
  3. Encrypt your report to that key (e.g., gpg --encrypt --armor --recipient [email protected] report.txt, or using your mail client's built-in OpenPGP support).
  4. Send the encrypted message to [email protected].

Encryption is optional for general or low-sensitivity reports, but strongly recommended for anything involving an unpatched vulnerability or evidence of active exploitation.

Encrypting vs. signing: Encrypting your report to our public key ensures only we can read it. If you'd also like to prove the report came from you (and let us verify it hasn't been tampered with), you can additionally sign it with your own PGP key before encrypting (gpg --sign --encrypt --armor --recipient [email protected] --local-user your-key-id report.txt). Signing is optional and only meaningful if you have your own key pair — it authenticates the sender, it does not replace encryption.

Please include as much of the following as you can:

What to expect

We review every report in good faith. Depending on the outcome of our assessment, a confirmed vulnerability may trigger further internal processes, including regulatory reporting where required by law.

Good-faith research

Vioside does not currently offer a formal safe-harbour commitment or bug bounty program. We ask that researchers:

Scope

This channel is for security vulnerabilities in Vioside's products with digital elements. For other issues (general support, billing, feature requests), please use [email protected].