Coordinated Vulnerability Disclosure (CVD) Policy

ICNS Global values the work of security researchers, customers, and the wider community in helping us keep our products safe. This policy explains how to report a vulnerability, what to expect from us, and the ground rules for responsible testing.

1. Scope

This policy covers all INS Technologies products with digital elements currently supported and on the market, including:

  • INS021-W
  • INS021-G
  • INS022
  • INS022-R4-50
  • INS022-R4-55
  • INS022-E-50
  • INS022-E-55
  • INS024
  • INS025
  • INS026
  • INS026-E-50
  • INS026-E-55
  • IRIS100 Site Gateway
  • IRIS200 Site Gateway
  • IRIS50
  • CEVIEW
  • IRIS-Note

2. How to report

Email security@ins-global.co.uk or use the reporting form on our security page. Please include:

  • The product and firmware/software version affected.
  • A clear description of the vulnerability and its potential impact.
  • Steps to reproduce, or a proof of concept, where possible.
  • Your contact details, if you would like a response (anonymous reports are accepted).

3. What to expect from us

Email security@ins-global.co.uk or use the reporting form on our security page. Please include:

  • Acknowledgement of your report within 5 business days.
  • An initial assessment and, where needed, a request for more information.
  • Regular updates while we investigate and remediate.
  • Credit in our acknowledgements, if you would like it, once the issue is resolved.

4. Our commitments under the Cyber Resilience Act

Where a vulnerability is being actively exploited, or an incident has a severe impact on product security, INS Technologies will notify the relevant national CSIRT and ENISA in line with the timelines set out in the Cyber Resilience Act: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report once a fix is available.

5. Responsible testing guidelines

We ask that reporting persons:

  • Avoid privacy violations, data destruction, and service disruption,
  • Only test against systems and accounts you own or have explicit permission to test.
  • Give us reasonable time to investigate and remediate before any public disclosure.
  • Do not access, modify, or exfiltrate data beyond what is necessary to demonstrate the issue.

6. Safe harbour

INS Technologies will not pursue legal action against reporting persons who make a good-faith effort to comply with this policy while reporting a vulnerability.

7. Disclosure timeline

We ask that details of a vulnerability are not made public until a fix or mitigation is available, or 90 days have passed since the report, whichever comes first, unless we agree otherwise with the reporter.