This policy is intended to give MAGNUM Heating Group B.V. (MHG BV) customers clear guidelines for conducting vulnerability discovery activities and to convey our preferences in how to submit discovered vulnerabilities to us. This policy describes what systems and types of research are covered under this policy, how to send us vulnerability reports, and how long we ask security researchers to wait before publicly disclosing vulnerabilities. We encourage you to contact us to report potential vulnerabilities in our systems.
GUIDELINES:
Under this policy, “research” means activities in which you:
SCOPE:
This vulnerability disclosure policy apply for internet connected products sold in the UK market and listed in the declaration of statement of compliance to the PSTI regulation
The following test methods are not authorized for testing vulnerabilities
Network denial of service (DoS or DDoS) tests or other tests that impair access to or damage a system or data
Physical testing (e.g. office access, open doors, tailgating), social engineering (e.g. phishing, vishing), or any other non-technical vulnerability testing
Any product not expressly listed in the statement of compliance, are excluded from scope. Additionally, vulnerabilities found in systems from our vendors fall outside of this policy’s scope and should be reported directly to the vendor according to their disclosure policy (if any). If you aren’t sure whether a system is in scope or not, contact us.
VULNERABILITY REPORTING PROCESS:
Any MHG BV customer can report a vulnerability issue observed on an MHG BV internet connected product on the following email address: info@magnumheatinggroup.com or Tel number: +31(0)166 609300. Reports may be submitted anonymously. If the customer share the contact information, we will acknowledge receipt of your report within 7 business days per email.
In order to help MHG BV triage and prioritize submissions, we recommend that your reports:
When the MHG BV customer choose to share his contact information with MHG BV , we commit to coordinating with you as openly and as quickly as possible:
SERVICE FOR SECURITY UPDATE:
The service for the security update of the MHG BV internet connected product is defined in the declaration of statement of compliance available in the website page.