Product Security

Product Security

Reporting security vulnerabilities responsibly

Ark Vision Systems recognizes the importance of information security to the integrity of our business operations. Protecting sensitive data and ensuring the cybersecurity of our products, systems, and information are fundamental to our business relationships. By promptly addressing security vulnerabilities and weaknesses in our products, we help minimize risks, prevent data breaches, and maintain the trust of our customers, partners, and employees.
We welcome responsible collaboration with customers, security researchers, suppliers, partners, employees, and the public.

Report a security vulnerability
If you discover a potential security vulnerability in one of our current products (excluding products that have been officially discontinued), we ask that you report it to us immediately. Please send your report to our Product Security Incident Response Team (PSIRT):

Email: cra-incident@ark-vision-systems.com

For a swift and effective investigation, your report should include the following information (where available):
  • • Your contact details
  • • Affected Ark Vision product (part number, serial number, software version)
  • • Clear description of the vulnerability or incident
  • • Potential impact and affected data
  • • Steps to reproduce the issue
  • • Date and time of the incident
  • • Relevant log files
  • • Information already publicly available or intended for publication
Coordinated Disclosure
Reported vulnerabilities are handled confidentially, responsibly, and transparently in accordance with the principles of Coordinated Vulnerability Disclosure (CVD).

Our goal is to rapidly assess vulnerabilities, initiate appropriate remediation measures, and keep the reporter informed of significant progress throughout the process.
As a general rule, vulnerabilities are only disclosed once a suitable fix is ​​available. The investigation period typically lasts up to 90 days. For particularly complex vulnerabilities or cases involving multiple manufacturers, this timeframe may be extended in consultation with the reporter.

Our Handling Process
Each incoming report is reviewed and evaluated by our PSIRT.
Step Timeframe
Acknowledgment of receipt Within 5 business days
Initial assessment Within 20 business days
Coordinated disclosure following the provision of a suitable fix.
Processing times may be adjusted for complex cases. We proactively inform the reporter of relevant status changes.

Security Reporting Portal
Once a product security vulnerability has been remediated, relevant information is published on the CERT@VDE reporting portal. This information is provided both as a plain-text advisory for users and in a machine-readable format, such as the CSAF (Common Security Advisory Framework) format.
Reporters who adhere to the coordinated disclosure process may be acknowledged on the relevant reporting portal upon request.

Confidentiality and Safe Harbor
All information provided as part of a security report is treated confidentially and used exclusively for investigating and remediating the reported issue. We support responsible vulnerability reporting and welcome collaboration with security researchers. Individuals who report vulnerabilities in good faith should not have to fear legal action.
This is subject to the following conditions:
  • • no data is accessed, modified, or deleted without authorization,
  • • no damage is caused to systems or services,
  • • the vulnerability is kept confidential until a fix is ​​provided or until the agreed end of the investigation period,
  • • no confidential information is disclosed to third parties.
Together, we can identify security risks early, remediate them responsibly, and sustainably strengthen the security of our products and systems.