LogoTurboSFV - Security
Overview
TurboSFV is gener­ally coded in a se­cure manner: Means no risky opera­tions in the program code, third party li­braries as less as possible and a proper testing of new func­tion­ality before releasing. However, coders are humans (at least here) and humans can make mistakes, so there is no guar­antee for a 100% error free software. There­fore, an error or a weakness could end up in a security vulner­abil­ity, which should be fixed as soon as possible.
Thus, similar to re­port­ing errors, we en­courage users to report us also pos­sible vulner­abil­ities.
Vulner­ability Dis­closure Policy
Contact details
A possible security vulner­abil­ity can be reported to
E-Mail:
  @tur
ritybosf
secuv.com
Regarding this kind of sen­sitive infor­mation, we support and prefer an en­crypted commu­nica­tion, so here is our public PGP Key.
Vulner­abil­ity reports will be accepted for a current version of TurboSFV, but not for third party soft­ware. Please include in the report the fol­low­ing infor­mation:
  • TurboSFV version number
  • Underlying oper­ating system in­clud­ing the build number.
  • Detailed descrip­tion of the pos­sible weakness and its ex­ploita­tion and how to repro­duce it.
  • A possible solution.
Our response
After receiving your vulner­abil­ity report, we will analyse the weakness and assess the possible ex­ploita­tion. Please give us suffi­cient time for that and reserve yourself a bit time for the case, that we need your help for a deeper analy­sis. We will send you a first response within five working days, and keep you updated about the progress.
In case of a con­firmed vulner­abil­ity, we will then develop a fix and make it avail­able for our cus­tomers. In the mean­time, if required, we will also share appro­priate infor­mation about the vulner­abil­ity with a corre­spond­ing report­ing plat­form, to ensure that the incident is properly commu­nicated.
Once the fix is ready and our cus­tomers had the oppor­tunity to patch, we will publicly dis­close the vulner­abil­ity. If you like, as acknowl­edgment for your contri­bution, we can name you as the re­searcher, who kindly helped us to find and fix the issue. Otherwise, we keep your personal data from our con­ver­sa­tion as confi­dential, as stated in our privacy policy. In any case, you will get a final response, in which the vulner­abil­ity report will be closed.
Thank you in ad­vance for helping us!
Security Advi­sories
Actually no security advi­sory hints avail­able.
Top
 
 
UKDE



Privacy PolicyVulnerability Disclosure Policy