Vulnerability Disclosure Policy

Last updated: 20. 8. 2026

Unipi Technology is committed to the safety and security of our customers and the environments where our products are used. We value the work of the security community and welcome reports of security vulnerabilities in our products, services and infrastructure. We recommend reading this policy fully before you report a vulnerability and acting in compliance with it. 

We do not offer monetary rewards for vulnerability disclosures. If you wish, we will credit you for the discovery in the related security advisory once the vulnerability is resolved. 

Scope 

This policy covers our products, cloud services, websites and online infrastructure. 


How to report 

Please submit your report through https://www.unipi.technology/security/report 

The form accepts reports of both web/infrastructure and product security vulnerabilities. Guidance on what information to provide, as well as the option to submit sensitive details encrypted, is available directly on the form page. 


What to Expect 

After you have submitted your report, we will respond within 5 working days and aim to triage your report within 10 working days. Priority for remediation is assessed by looking at the impact, severity and exploit complexity. 


Guidance 

To keep your research safe for the users of our products, we ask that you: 
  • comply with data protection rules and respect the privacy of our users, staff, partners, services and systems; securely delete any data retrieved during your research once it is no longer needed; 
  • do not access, modify or delete data that is not yours, beyond what is necessary to demonstrate the vulnerability; 
  • do not use destructive or high-intensity scanning tools, and do not attempt any form of denial of service against our production services; 
  • do not disrupt services or installations operated by our customers — wherever possible, test against your own devices; 
  • do not use social engineering, phishing or physical attacks against our staff or infrastructure
  • do not publicly disclose the vulnerability before a fix is available and public release has been coordinated with us. 


Legalities 

This policy is designed to be compatible with common vulnerability disclosure good practice. As long as your actions are in good faith and comply with this policy, Unipi Technology will not pursue legal action against you. This policy does not give you permission to act in any manner inconsistent with the law, or which might cause Unipi or partner organizations to be in breach of any legal obligations. 


Questions 

Questions or suggestions regarding this policy are welcome — you can send them through the report form or our standard support channels.