Vulnerability Disclosure Policy
1. Purpose
Lasernet Group welcomes reports from security researchers, customers, partners, and the wider security community who identify potential security vulnerabilities in our products, services, or digital assets.
This policy explains:
- How vulnerabilities can be reported to us
- What information we need to investigate a report
- What researchers can expect from us during the investigation process
- The standards of conduct expected when conducting security research against our systems
- Our commitment to responsible and coordinated vulnerability disclosure
We are committed to maintaining effective vulnerability handling processes throughout the lifecycle of our products and services and to working collaboratively with security researchers to improve security.
2. Scope
This policy applies to all Products with Digital Elements (PDEs) and associated services provided by Lasernet Group.
This includes software products, cloud-hosted services, supporting infrastructure, customer-facing platforms, and other digital assets owned, operated, maintained, or supported by Lasernet Group.
3. Out of Scope
This policy does not apply to:
- Systems, infrastructure, software, or services not owned or managed by Lasernet Group
- Third-party products that are not part of a Lasernet Group offering
- Vulnerabilities requiring destructive testing methods
- Reports relating solely to security best-practice recommendations without a demonstrable security impact
- Denial-of-Service (DoS) or Distributed Denial-of-Service (DDoS) testing
Where a vulnerability is identified in a third-party product, researchers should report it to the relevant vendor.
4. How to Report a Vulnerability
Vulnerabilities should be reported using one of the following approved channels:
- Email: disclosure@lasernetgroup.com
- Customer Support Portal: https://support.lasernetgroup.com/
All reports should include, where possible:
- Product name and version
- A description of the vulnerability
- Steps to reproduce the issue
- Proof of concept or supporting evidence
- Potential security impact
- Security Researcher contact details
- Any proposed disclosure timeline
Providing complete information helps us investigate and remediate vulnerabilities more efficiently.
5. What You Can Expect From Us
5.1 Acknowledgement
We will:
- Acknowledge receipt of your report within 3 business days
- Provide a unique tracking reference
- Confirm the next steps of the investigation process
5.2 Validation and Triage
Following acknowledgement, appropriate product, security, support and compliance personnel will:
- Assess whether the report is within scope
- Validate the reported vulnerability
- Assess severity and business impact
- Identify affected products, versions, customers, or environments
- Request additional information if required
5.3 Progress Updates
Where investigations remain open, we will aim to provide progress updates at appropriate intervals.
Updates may include:
- Validation outcomes
- Severity assessments
- Planned remediation actions
- Expected disclosure activities
- Anticipated remediation timelines
5.4 Remediation
We will seek to remediate validated vulnerabilities in a manner proportionate to their risk and operational impact.
Not all vulnerabilities will result in an immediate software fix. Outcomes may include:
- Immediate remediation
- Remediation in a future release
- Mitigation through compensating controls
- Formal acceptance of residual risk
- Determination that the issue is not a vulnerability or is outside scope
5.5 Closure
Upon completion of our assessment or remediation activities, we will notify the Security Researcher of the final outcome wherever contact details have been provided.
5.6 Coordinated Vulnerability Disclosure
We support responsible and coordinated disclosure.
Where a reported vulnerability is validated:
- We will work with the Security Researcher to coordinate public disclosure
- Public disclosure should normally be delayed until a fix or mitigation is available
- Disclosure timelines may be adjusted where there is evidence of active exploitation or significant customer risk
- Security Researchers should notify us before publishing details to ensure affected customers have appropriate guidance available
6. Researcher Conduct Requirements
When conducting research under this policy, Security Researchers must:
- Act in good faith
- Comply with applicable laws and regulations
- Avoid accessing more data than necessary to demonstrate a vulnerability
- Respect the privacy of customers, employees, and other users
- Securely delete any data obtained during testing once it is no longer required
- Immediately stop testing if unintended access to sensitive information occurs and report the issue.
Security Researchers must not:
- Modify, destroy, or manipulate data
- Disrupt services or systems
- Conduct denial-of-service testing
- Use invasive or destructive scanning methods
- Conduct phishing, social engineering, or physical attacks
- Demand payment or compensation in exchange for disclosure
- Publicly disclose vulnerabilities before coordinating with Lasernet Group
- Share information obtained during testing with unauthorised parties
7. Safe Harbour
Lasernet Group recognises the value of good-faith security research.
Provided Security Researchers:
- Act in good faith
- Follow this policy
- Avoid actions that disrupt services, compromise privacy, or violate the law
- Promptly report discovered vulnerabilities
Lasernet Group will not initiate legal action against researchers solely for conducting research activities that comply with this policy.
This policy does not authorise actions that are unlawful or that would cause Lasernet Group to breach legal or regulatory obligations.
8. Recognition
Lasernet Group does not currently operate a bug bounty programme and does not offer financial rewards for vulnerability reports. However, we appreciate responsible disclosures and may acknowledge researchers publicly where appropriate and agreed by both parties.
9. Records and Governance
Lasernet Group maintains records of vulnerability disclosures, including:
- Vulnerability reports
- Assessment and triage decisions
- Communications with researchers
- Investigation records
- Remediation actions
- Disclosure decisions
- Closure evidence
These records support regulatory compliance, audit requirements, product security activities, and vulnerability management processes.
10. Contact Information
Security Vulnerability Reporting Email: disclosure@lasernetgroup.com
Support Portal: https://support.lasernetgroup.com/
Last updated: 25th September 2026