Product Security
Reporting security vulnerabilities responsibly
Ark Vision Systems recognizes the importance of information security to the integrity of our business operations. Protecting sensitive data and ensuring the cybersecurity of our products, systems, and information are fundamental to our business relationships. By promptly addressing security vulnerabilities and weaknesses in our products, we help minimize risks, prevent data breaches, and maintain the trust of our customers, partners, and employees.We welcome responsible collaboration with customers, security researchers, suppliers, partners, employees, and the public.
Report a security vulnerability
If you discover a potential security vulnerability in one of our current products (excluding products that have been officially discontinued), we ask that you report it to us immediately. Please send your report to our Product Security Incident Response Team (PSIRT):
Email: cra-incident@ark-vision-systems.com
For a swift and effective investigation, your report should include the following information (where available):
- • Your contact details
- • Affected Ark Vision product (part number, serial number, software version)
- • Clear description of the vulnerability or incident
- • Potential impact and affected data
- • Steps to reproduce the issue
- • Date and time of the incident
- • Relevant log files
- • Information already publicly available or intended for publication
Reported vulnerabilities are handled confidentially, responsibly, and transparently in accordance with the principles of Coordinated Vulnerability Disclosure (CVD).
Our goal is to rapidly assess vulnerabilities, initiate appropriate remediation measures, and keep the reporter informed of significant progress throughout the process.
As a general rule, vulnerabilities are only disclosed once a suitable fix is available. The investigation period typically lasts up to 90 days. For particularly complex vulnerabilities or cases involving multiple manufacturers, this timeframe may be extended in consultation with the reporter.
Our Handling Process
Each incoming report is reviewed and evaluated by our PSIRT.
| Step | Timeframe |
|---|---|
| Acknowledgment of receipt | Within 5 business days |
| Initial assessment | Within 20 business days |
Processing times may be adjusted for complex cases. We proactively inform the reporter of relevant status changes.
Security Reporting Portal
Once a product security vulnerability has been remediated, relevant information is published on the CERT@VDE reporting portal. This information is provided both as a plain-text advisory for users and in a machine-readable format, such as the CSAF (Common Security Advisory Framework) format.
Reporters who adhere to the coordinated disclosure process may be acknowledged on the relevant reporting portal upon request.
Confidentiality and Safe Harbor
All information provided as part of a security report is treated confidentially and used exclusively for investigating and remediating the reported issue. We support responsible vulnerability reporting and welcome collaboration with security researchers. Individuals who report vulnerabilities in good faith should not have to fear legal action.
This is subject to the following conditions:
- • no data is accessed, modified, or deleted without authorization,
- • no damage is caused to systems or services,
- • the vulnerability is kept confidential until a fix is provided or until the agreed end of the investigation period,
- • no confidential information is disclosed to third parties.