At CenoBots, we are committed to maintaining a high level of cybersecurity for our products and services. We value the contributions of security researchers, customers, partners, and the broader community in helping us identify and address potential security vulnerabilities.
We encourage you to read this policy before submitting a vulnerability report so that reports can be handled safely, efficiently, and responsibly.
This policy sets out the process for reporting potential security vulnerabilities affecting CenoBots products, solutions, and services.
This policy applies to:
The following are not covered by this policy:
If you believe you have discovered a security vulnerability, please report it to CenoBots at:
CenoBots also publishes a security.txt file to help security researchers identify the official channel for reporting vulnerabilities:
https://www.cenobots.com/.well-known/security.txt
Please include as much of the following information as possible:
When submitting a report, please:
Upon receiving a report, CenoBots will begin investigating the potential vulnerability in accordance with our internal procedures. We may contact you for additional information if needed to reproduce or validate the issue.
If the vulnerability is confirmed, CenoBots will assess its severity, affected products and versions, potential customer impact, and required remediation measures.
If a vulnerability is validated, CenoBots will develop a remediation or mitigation plan. The priority and timeline for remediation will depend on the severity of the vulnerability, the affected products, the potential safety or cybersecurity impact, and the time required for development, testing, and deployment of updates.
Where appropriate, remediation may include software updates, firmware updates, configuration changes, customer advisories, temporary mitigations, or other corrective actions.
For products placed on the European Union market, CenoBots may be required to report actively exploited vulnerabilities or severe cybersecurity incidents to the relevant authorities in accordance with applicable legislation, including the EU Cyber Resilience Act.
Once the vulnerability has been analyzed and handled, CenoBots may disclose relevant information to affected customers, partners, regulators, or other relevant parties.
We aim to balance transparency with the need to reduce risk and give affected parties sufficient time to apply necessary fixes or mitigations. Public advisories may therefore be delayed where immediate disclosure could increase cybersecurity or safety risks.
CenoBots may acknowledge individuals, organizations, or companies that voluntarily report valid vulnerabilities and assist us in improving cybersecurity, unless they request anonymity.
CenoBots will not take legal action against parties who make a good faith effort to comply with this policy, provided that they:
We ask that you do not publicly disclose the vulnerability until CenoBots has had a reasonable opportunity to investigate, remediate, and coordinate disclosure with affected parties.
Please coordinate any public disclosure timeline with us in advance.
CenoBots does not currently operate a paid bug bounty program. Submission of a vulnerability report does not create any entitlement to compensation.
Where appropriate, CenoBots may publicly acknowledge valid vulnerability reports unless the reporter requests anonymity.
Throughout the vulnerability disclosure process, you are expected to:
This policy does not constitute a waiver of any legal rights or create obligations beyond those explicitly stated. CenoBots reserves the right to take legal action in cases of non-compliance with this policy or applicable law.