Policy for Reporting and Managing Security Vulnerabilities
TSec s.r.l. (hereinafter referred to as “TSec”) recognizes cybersecurity as an essential element in ensuring the security, reliability, and resilience of its products and considers the management of security vulnerabilities an integral part of the development process and product lifecycle.
In accordance with the applicable principles and obligations set forth in Regulation (EU) 2024/2847—the Cyber Resilience Act (CRA), TSec has defined and adopted an internal procedure for managing security vulnerabilities that may be identified in its products.
The procedure governs, among other things, the receipt, logging, assessment, management, and resolution of reported or identified vulnerabilities, as well as, where applicable, the implementation of necessary corrective measures and related communication activities, in accordance with applicable regulations.
Reporting Vulnerabilities
TSec encourages customers, partners, and other stakeholders to responsibly report any security vulnerabilities found in TSec products.
Reports can be sent to TSec’s Product Security Incident Response Team (PSIRT) at the following address:
Reports are accepted in Italian or English.
To enable a timely and effective assessment of the report, please include the following information, if available:
- identification of the affected product and version;
- a detailed description of the vulnerability;
- the conditions and steps required to reproduce the vulnerability;
- any proof-of-concept code;
- an assessment of the security impact, if available;
- any information regarding possible mitigation measures.
TSec is committed to handling received reports in accordance with its vulnerability management procedure and in compliance with the obligations set forth in applicable regulations.
Information regarding vulnerabilities will be treated with due confidentiality and will be used exclusively for purposes related to the assessment, management, and mitigation of security risks, subject to applicable laws and regulations.
TSec encourages responsible collaboration in reporting vulnerabilities, with the goal of continuously improving the security and resilience of its products and contributing to the protection of its customers and users.