Unipi Technology is committed to the safety and security of our customers and the environments where our products are used. We value the work of the security community and welcome reports of security vulnerabilities in our products, services and infrastructure. We recommend reading this policy fully before you report a vulnerability and acting in compliance with it.
We do not offer monetary rewards for vulnerability disclosures. If you wish, we will credit you for the discovery in the related security advisory once the vulnerability is resolved.
Scope
This policy covers our products, cloud services, websites and online infrastructure.
How to report
Please submit your report through
https://www.unipi.technology/security/report The form accepts reports of both web/infrastructure and product security vulnerabilities. Guidance on what information to provide, as well as the option to submit sensitive details encrypted, is available directly on the form page.
What to Expect
After you have submitted your report, we will respond within 5 working days and aim to triage your report within 10 working days. Priority for remediation is assessed by looking at the impact, severity and exploit complexity.
Guidance
To keep your research safe for the users of our products, we ask that you:
- comply with data protection rules and respect the privacy of our users, staff, partners, services and systems; securely delete any data retrieved during your research once it is no longer needed;
- do not access, modify or delete data that is not yours, beyond what is necessary to demonstrate the vulnerability;
- do not use destructive or high-intensity scanning tools, and do not attempt any form of denial of service against our production services;
- do not disrupt services or installations operated by our customers — wherever possible, test against your own devices;
- do not use social engineering, phishing or physical attacks against our staff or infrastructure
- do not publicly disclose the vulnerability before a fix is available and public release has been coordinated with us.
Legalities
This policy is designed to be compatible with common vulnerability disclosure good practice. As long as your actions are in good faith and comply with this policy, Unipi Technology will not pursue legal action against you. This policy does not give you permission to act in any manner inconsistent with the law, or which might cause Unipi or partner organizations to be in breach of any legal obligations.
Questions
Questions or suggestions regarding this policy are welcome — you can send them through the report form or our standard support channels.