ICNS Global values the work of security researchers, customers, and the wider community in helping us keep our products safe. This policy explains how to report a vulnerability, what to expect from us, and the ground rules for responsible testing.
This policy covers all INS Technologies products with digital elements currently supported and on the market, including:
Email security@ins-global.co.uk or use the reporting form on our security page. Please include:
Email security@ins-global.co.uk or use the reporting form on our security page. Please include:
Where a vulnerability is being actively exploited, or an incident has a severe impact on product security, INS Technologies will notify the relevant national CSIRT and ENISA in line with the timelines set out in the Cyber Resilience Act: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report once a fix is available.
We ask that reporting persons:
INS Technologies will not pursue legal action against reporting persons who make a good-faith effort to comply with this policy while reporting a vulnerability.
We ask that details of a vulnerability are not made public until a fix or mitigation is available, or 90 days have passed since the report, whichever comes first, unless we agree otherwise with the reporter.