Skip to content
Accueil » Reporting a Security Vulnerability

Reporting a Security Vulnerability

Our Commitment

We have developed our products based on the “Secure By Design” philosophy. The security of our products and services is a priority.

We place great importance on vulnerability reports from our customers, partners, and anyone else who wishes to help improve the security of our solutions.

If you believe you have identified a vulnerability affecting one of our products or services, we encourage you to report it to us so that our team can analyze it and take appropriate action.

Scope: This policy applies to all hardware and software products sold by ODALID (badge readers, couplers, related IoT solutions) as well as our digital services. Vulnerabilities affecting third-party products integrated into our solutions must also be reported to us; we will forward them to the relevant supplier.

How to Report a Vulnerability

To submit a security report, contact our security team at the following address preferably with PGP encryption

security😼odalid.com

To help us analyze your report, please include the following information:

  • Contact name
  • Name of the affected product;
  • Version of the product used;
  • Detailed description of the vulnerability;
  • Steps to reproduce the issue;
  • Identified potential impact;
  • Useful technical details (screenshots, logs, proof-of-concept).
  • the Common Vulnerability Scoring System Version 3.0 Calculator

Responsible Disclosure Guidelines

We ask anyone who discovers a vulnerability to:

  • not exploit the vulnerability beyond the purpose of demonstration;
  • not access data that does not belong to them;
  • not disrupt a service;
  • wait to engage in dialogue before disclosing the vulnerability.

We are committed to not taking legal action against individuals acting in good faith in accordance with the rules set forth above. If a third party were to initiate legal action in connection with a report made in accordance with this policy, we will take the necessary steps to make it clear that the researcher’s action was authorized.

Processing Your Report

Every report we receive is logged, analyzed, and assessed by our security team. We are committed to acknowledging receipt of your report within 5 business days. After qualification, each report is prioritized based on its severity (CVSS score): critical and high-severity vulnerabilities are handled as a priority by our teams; vulnerabilities rated as medium or low are addressed as part of our regular development cycles. The time required to fix a vulnerability depends on its technical complexity and, where applicable, on constraints specific to hardware updates; we keep the reporter informed of the progress of the fix.

Additional Information

Security reports are handled confidentially and solely for the purpose of improving the security of our products and services. Customers who have reported a vulnerability, as well as those affected by a fix, are notified individually and confidentially. The publication is available on our support platform.

Thank you to everyone who helps strengthen the security of our solutions.