Skip to content

Product security

Report a security vulnerability

For security vulnerabilities affecting Gunnebo’s IT estate, gunnebo.com, or other internet-facing services, please refer to our Coordinated Vulnerability Disclosure (CVD) page and use the reporting process described there.

Scope and responsible disclosure 

This process applies primarily to products with digital elements and digital solutions that are supported and maintained by Chubbsafes. Submission of a report does not create any contractual relationship, entitlement to compensation, or obligation on our part to implement a specific remediation measure or disclosure approach. We will not pursue legal action solely on the basis of good-faith security research conducted in accordance with these guidelines and applicable law.

Choose your reporting route

How to report a vulnerability

This reporting channel is intended for reporting vulnerabilities affecting products with digital elements and related product security concerns. If you believe you have discovered a security vulnerability in those products, please use the appropriate form below to report potential product security vulnerabilities based on your role. Personal data submitted through a vulnerability report will be processed in accordance with our Privacy Notice.

Supplier report

Report a potential vulnerability in a product, component, service or technology supplied to Chubbsafes.

Customer or researcher report

Report a potential vulnerability in a Chubbsafes product or related digital service as a customer, researcher, partner or other external party.

Responsible disclosure guidelines

We kindly ask that reporters:

Investigation period
Allow us a reasonable period to investigate and remediate the issue before any public disclosure.

Responsible testing
Avoid exploiting the vulnerability beyond what is necessary to demonstrate it

Data protection
Do not access, modify or delete data belonging to others.

Direct reporting
Contact us directly through the appropriate reporting form.


Response process

What happens after you submit a report

We follow coordinated vulnerability disclosure principles. The exact process and timing may vary depending on the nature and complexity of the issue, but it will normally include the following stages:

01

Submission received

We aim to acknowledge receipt of vulnerability reports within a reasonable timeframe.

02

Initial assessment

We review the information and may request further details. Where required, we comply with applicable regulatory reporting obligations

03

Investigation and action

We investigate the issue and determine the appropriate remediation or mitigation.

04

Coordinated communication

Where relevant, we coordinate remediation and disclosure with the reporter.

Information submitted through this process may be shared within the Chubbsafes businesses and with relevant service providers, suppliers, regulators or authorities where necessary to investigate, mitigate or comply with applicable legal obligations.


Contact

General product security enquiries

For enquiries that are not related to a digital product vulnerability report, please use the general contact page.