Reporting Guidelines
Please report any potential or real security vulnerability claim to the Traka Product Security Team via e-mail.
Traka values the insight and commitment of security researchers and other vulnerability investigators to make the world a safer place by discovering vulnerabilities of security solutions and providing mechanisms to privately report them with legitimacy and integrity. Responsible disclosure ensures that security access infrastructure is tested and proven reliable. Moreover, the commitment to mitigate vulnerabilities is reassuring for our customers and the security industry as a whole. The following is Traka’s responsible disclosure policy:
We ask the security researcher community to work with Traka to coordinate the public disclosure of a vulnerability. Pre-maturely revealing a vulnerability publicly without first notifying Traka could hurt organizations, exposing sensitive information and putting people and organizations in danger of malicious attacks. This is why Traka strongly advocates a two-step process: first, private disclosure of a potential vulnerability to Traka. Once the vulnerability is validated, resolved and Traka and its customers provided a reasonable time to deploy, Traka coordinates the public disclosure, which includes the recognition of the security researcher’s discovery, confirming that credit is given to the right person(s). We also ask that researchers to recognize that our action to investigate, validate and remediate reported vulnerabilities varies based on complexity and severity. We will communicate expected timelines, changes and collaborate where possible. In addition, we request that researchers do not perform Denial of Service mechanisms, compromise Traka user infrastructure or personal information. CALL TO ACTION
|
Please report any potential or real security vulnerability claim to the Traka Product Security Team via e-mail.
Traka values insight from the security research community and welcomes disclosure and collaboration with this community.
Documentation related to Traka Product Security Advisories.