Reporting security vulnerabilities
How to report a vulnerability to us and how we handle it.
Reporting a vulnerability
Have you discovered a possible security vulnerability in a Netstream service or system? Please report it to our Helpdesk without delay.
The following information is helpful:
- the affected system, URL or service
- a description of the vulnerability and its possible impact
- steps to reproduce it, with a proof of concept if available
- your contact details for any questions
What we do
We confirm receipt of your report within one working day, examine the vulnerability and inform you of the next steps. We assess and fix confirmed vulnerabilities in line with our vulnerability management process. On request, we will let you know when the vulnerability has been fixed.
Please note
- Do not exploit the vulnerability beyond what is needed to demonstrate it.
- Do not access third-party data, and do not change or delete any data.
- Do not carry out tests that affect availability, such as denial-of-service attacks.
- Do not use social engineering or physical attacks.
- Do not publish the vulnerability until we have fixed it or we have agreed on it with you.
Confidentiality
We treat your report confidentially and do not pass your data on to third parties without your consent. If you follow these rules, we will not take legal action.