PSTI CVD Policy
Coordinated Vulnerability Disclosure Statement
Purmo Group (UK) Ltd is committed to ensuring the safety and security of our products and services. Purmo Group (UK) Ltd develops and deploys advanced best practice security and privacy features for our products and services. Purmo Group (UK) Ltd operates under a global coordinated vulnerability disclosure policy, which guides our incident management and all risk assessment activities relating to potential security and privacy vulnerabilities identified in our products and services. Purmo Group (UK) Ltd supports coordinated vulnerability disclosure and encourages vulnerability testing by security researchers and by customers, with responsible reporting to Purmo Group (UK) Ltd.
Coordinated Vulnerability Disclosure Process
When submitting reports of vulnerability findings, please ensure the following procedures are followed, for safe and efficient support.
Reporting Procedure:
Please email submissions to us at [email protected]
Please include in the e-mail subject the acronym: ‘CVD’ and provide us with your reference/advisory number and sufficient contact information, such as your organisation and contact name so that we can get in touch with you.
Providing a technical description of the concern or vulnerability:
a) Please provide information on which specific product you tested, the brand, including product name and version number; the technical infrastructure tested, including operating system and version; and any relevant additional information, such as network configuration details.
b) For web-based services, please provide the date and time of testing, URLs, the browser type and version, as well as the input provided to the application.
To help us to verify the issue, please provide any additional information, including details on the tools used to conduct the testing and any relevant test configurations. If you wrote specific proof-of-concept or exploit code, please provide a copy. Please ensure all submitted code is clearly marked as such.
If you have identified specific threats related to the vulnerability, assessed the risk, or have seen the vulnerability being exploited, please provide that information.
When possible, provide the report in English to expedite the process.
Product Security Vulnerability Report Assessment and Action:
Purmo Group (UK) Ltd will acknowledge receiving your report within two business days.
Purmo Group (UK) Ltd will provide you with a unique tracking number for your report.
Purmo Group (UK) Ltd will assign a contact person to each case.
Purmo Group (UK) Ltd will investigate the report.
Purmo Group (UK) Ltd will keep you informed on the status of your report.
If the vulnerability is actually in a 3rd party component which is part of our product/service, we will refer the report to that 3rd party and advise you of that notification. To that end, please inform us whether it is permissible in such cases to provide your contact information to the 3rd party.
Upon receiving a vulnerability report, Purmo Group (UK) Ltd will:
a) Verify the reported vulnerability.
b) Asses the risk level of the reported vulnerability.
c) Work on a resolution.
d) Perform QA/validation testing on the resolution.
e) Release the resolution.
f) Share lessons learned with development teams.
Purmo Group (UK) Ltd will use existing customer notification processes to manage the release of patches or security fixes, which may include direct customer notification or public release of an advisory notification on our website.
Vulnerability Risk Classification
Negligible Risk |
|
Low Risk |
|
Medium Risk |
|
High Risk |
|
Critical Risk |
|
Notice:
In case you decide to share any information with Purmo Group (UK) Ltd, you agree that the information you submit will be considered as non-proprietary and non-confidential and that Purmo Group (UK) Ltd is allowed to use such information in any manner, in whole or in part, without any restriction. Furthermore, you agree that submitting information does not create any rights for you or any obligation for Purmo Group (UK) Ltd.
Last update: 16/01/2026