Super B delivers products that offer the best quality and reliability. The Super B Product Security Incident Response Team (PSIRT) supports this by helping to resolve security issues identified in Super B products by external security researchers, partners, or customers.
Super B PSIRT coordinates measures in case of (potential) security incidents with Super B engineers and development teams, including establishing an appropriate response plan, and maintaining regular communication with the reporting party. Super B encourages coordinated disclosure of vulnerabilities and we kindly ask the reporting party to keep the vulnerability confidential until Super B makes a fix available.
Everyone is encouraged to report identified vulnerabilities, regardless of service contracts or product lifecycle status. We welcome vulnerability reports directly from researchers, industry groups, CERTs (Computer Emergency Response Teams), partners and any other source. We respect the interests of the reporting party (anonymous reports are also welcome) and agree to address any vulnerability that is reasonably believed to be related to our products or services. We strongly urge reporting parties to perform a coordinated disclosure, as immediate public disclosure puts our customers' systems at unnecessary risk.
We kindly ask the reporting party to not share or publicize an unresolved vulnerability with or to third parties.
By following the Super B Responsible Security Disclosure Policy, the Super B PSIRT and associated development organizations will use reasonable efforts to:
Our standard response time to acknowledge receipt of vulnerability reports is 4 working days (this means that it excludes weekends and public holidays in the Netherlands). Status updates of reported vulnerabilities are given when relevant information becomes available.
Super B agrees not to pursue claims against reporting parties related to disclosures submitted to us providing the following:
Super B appreciates the efforts made by the reporting party in identifying the vulnerability and working with us to ensure the safety of Super B customers.
We thank you for going out of your way to improve the security and safety of our customers and the Internet community as a whole.