Remion Security Vulnerability Reporting Policy and Good-Faith Expectations

Purpose

Remion welcomes good-faith reporting of security vulnerabilities and related cybersecurity deviations affecting Remion-controlled products, services, and public-facing resources.

This policy explains how to report a security issue to Remion, what kinds of activity Remion considers in scope for good-faith reporting, and how Remion coordinates handling of disclosures.

What To Report

This policy is intended to support good-faith security research and reporting concerning Remion-controlled products, services, and public-facing assets.

It describes the kinds of activity and targets for which Remion is prepared to receive reports and coordinate handling. It is not a general authorization to test any environment in which Remion components may appear.

Scope

Findings related to Remion-controlled public-facing products, services, and other assets described in this policy are the intended scope for good-faith reporting activity and testing under this policy.

  • vulnerabilities in Remion products with digital elements
  • vulnerabilities in third-party components where the issue affects a Remion product
  • vulnerabilities or security deviations affecting Remion-controlled websites, domains, DNS configurations, certificates, email, and other public networking infrastructure
  • vulnerabilities or security deviations affecting Remion-managed hosted environments and services within the agreed Remion operating scope
  • findings related to Remion products or components that are identified in customer solutions or customer environments, where the finding concerns the Remion product or component itself

If you are unsure whether an issue or resource is in scope, you may contact Remion for further clarification at security@remion.com.

Out of scope

  • Customer-owned or customer-managed environments are not in scope for testing under this policy, even where they use Remion products or components.
  • Remion does not provide permission to test any environment that belongs to a customer and cannot grant such permission on a customer’s behalf.
  • Findings related to Remion products or components that are identified in customer-owned or customer-managed environments during authorized security audits may be reported to Remion.
  • Other third-party systems, services, or infrastructure that Remion does not control are not in scope for testing under this policy.

Most of Remion’s public web resources also provide a /.well-known/security.txt file. This file helps security researchers find the correct reporting contact and the location of this policy, and may also help them identify public Remion resources that fall within this policy’s scope.

Good-Faith Reporting Expectations

Remion expects good-faith reporters to follow these expectations:

  • limit activity to what is necessary to identify and demonstrate the issue
  • limit demonstration of SQL injection or similar database access issues to non-sensitive proof, such as database version information, and do not read, tamper, or exfiltrate data, manipulate permissions, or perform similar actions
  • limit demonstration of remote code execution to non-persistent informational commands, such as date or an operating-system-version command
  • do not establish persistence or continued presence in any Remion system
  • do not exfiltrate, download, modify, delete, or otherwise access data beyond what is strictly necessary to demonstrate the issue
  • do not cause denial-of-service, service degradation, destructive effects, malware deployment, or extortion activity
  • do not attempt social engineering, phishing, physical intrusion, or credential theft
  • if planned activity is borderline or not clearly covered by these expectations, ask Remion for clarification before proceeding using security@remion.com
  • do not disclose vulnerability information publicly or to other third parties before coordinated handling has progressed sufficiently, except where disclosure to Traficom / NCSC-FI, another CSIRT, ENISA, another competent authority, or disclosure required by law or safety reasons makes that necessary
  • do not report purely theoretical issues without a practical proof-of-concept showing real exploitability, such as clickjacking of non-actionable information sites or missing headers without practical consequences

These expectations do not grant a general authorization for penetration testing or intrusive activity.

Remion does not operate a public bug bounty or reward program under this draft policy.

How To Report

Email address security@remion.com is Remion’s primary contact point for coordinated vulnerability disclosures.

Disclosures may also be coordinated through a CSIRT, including Traficom / NCSC-FI where applicable. Where relevant, official coordination may also involve ENISA or another competent authority.

To help Remion assess the issue, include where possible:

  • affected product, service, URL, domain, component, or other asset
  • version information, environment details, or relevant identifiers
  • steps to reproduce
  • potential impact
  • logs, screenshots, proof-of-concept material, or other supporting evidence
  • your contact details

What Remion Commits To

Remion aims to:

  • provide a clear human-handled reporting path through security@remion.com
  • acknowledge receipt of good-faith reports within 3 business days
  • review and triage the report internally
  • request clarification if needed
  • route the matter to the correct internal handling process
  • coordinate handling in good faith with reporters acting within this policy
  • validate and, where necessary, remediate vulnerabilities before detailed information is disclosed to third parties or to the public

Remion does not provide fixed remediation deadlines for reported security deviations, but it aims to act without undue delay in proportion to the risk level of the reported issue.

Remion does not provide internal details about the mitigation process for reported security deviations.

Where legal, regulatory, customer, or incident-response obligations apply, Remion may need to coordinate handling with other parties, including customers, component maintainers, NCSC-FI, other CSIRTs, ENISA, other competent authorities, or other responsible manufacturers.

Some disclosures may require confidential handling while validation, remediation, customer coordination, or official coordination is ongoing.