Valamis Security

Responsible Disclosure

At the Valamis Group Oy we consider the security of our systems a top priority. But no matter how much effort we put into system security, there can still be vulnerabilities present.
If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. We would like to ask you to help us better protect our clients and our systems.

Please do the following:

  • Do provide sufficient information to reproduce the problem, so we will be able to resolve it as quickly as possible. Usually, the IP address or the URL of the affected system and a description of the vulnerability will be sufficient, but complex vulnerabilities may require further explanation,
  • E-mail your findings to security@valamis.com. Encrypt your findings using our PGP key (see below) to prevent this critical information from falling into the wrong hands,
  • Always comply with data protection rules and not violate the privacy of any data. You must not, for example, share, redistribute or fail to properly secure data retrieved from the systems or services,
  • Securely delete all data retrieved during your research as soon as it is no longer required or within 1 month of the vulnerability being resolved, whichever occurs first (or as otherwise required by data protection law).

Please do NOT do the following:

  • Do not break any applicable law or regulations.
  • Do not take advantage of the vulnerability or problem you have discovered, for example by downloading more data than necessary to demonstrate the vulnerability or deleting or modifying other people’s data,
  • Do not reveal the problem to others until it has been resolved,
  • Do not use attacks on physical security, social engineering, distributed denial of service, spam or applications of third parties,
  • Do not modify data in our systems or services more than necessary to demonstrate the vulnerability,
  • Do not use high-intensity invasive or destructive scanning tools to find ,
  • Do not use attempt any form of denial of service, e.g. overwhelming a service with a high volume of requests,
  • Do not disrupt the services or systems,
  • Do not social engineer, ‘phish’ or physically attack Valamis staff or infrastructure,
  • Do not demand financial compensation in order to disclose any vulnerabilities.

What we promise:

  • We will respond to your report with our evaluation of the report and an expected resolution date,
  • If you have followed the instructions above, we will not take any legal action against you in regard to the report,
  • We will handle your report with strict confidentiality, and not pass on your personal details to third parties without your permission,
  • We will keep you informed of the progress towards resolving the problem,
  • In the public information concerning the problem reported, we will give your name as the discoverer of the problem (unless you desire otherwise),

We strive to resolve all problems as quickly as possible, and we would like to play an active role in the ultimate publication on the problem after it is resolved.

Legalities:

This policy is designed to be compatible with common vulnerability disclosure good practice. It does not give you permission to act in any manner that is inconsistent with the law, or which might cause Valamis to be in breach of any legal obligations.

Valamis Vulnerability Disclosure Policy Public PGP Key

You can use our public key to encrypt and secure messages you sent to security@valamis.com.

Valamis Vulnerability Disclosure Policy <security@valamis.com> (8A0649E7EACA3138)

You can find it published here
https://keys.openpgp.org/search?q=8A0649E7EACA3138

Please import the public key into your local OpenPGP Key-Manager:

-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBGR/hgIBEADc+t7LhuN3ijl2Q5QBu6v4WiuV4brOWkRZnlTGmNViXPPlmAHd
wnTSvA6A2gGlYE6gUeNTvsuhihxuRf3Ar6FbmvqgtopYyu+Sj/IU8CJ5xDwtxXYr
xjxUnvlRXOyI1RcbEI7hJaPZphz4fGymZEmthwqN/03ifpZuYPJxxo2kW13yWSoF
wZcsJMm7aCM4IhcXDI8qVf63bkcVZL9Gt1Zf9fAHLHkUoW6GfUyZnyRDag6+6x94
y4LBbPmwnP83dxteW/cIRipe41ztE5pFLtMIP89xWViKPuSDgzLa7DXeaBko1UI2
4K0Oj7OonD5OBJgJZeka4ppNw7EZY7UkHveRpWEiSk7o2yXiyohanZdohnk79p2j
JMfbWI3KDls4tM52bAZqAgnVTtn+PeRvipUo3h4f0Gr5oYZKOfu2LNOjYqRCawby
hWM5huVryMM4q3/sj71KW6NJHBWuvHN3tZQ2IDUZEkJjujRGlF4MTNsuUM4KJeJn
KB4ZV+g63kG4DJ0+6UfOWf2qclQtjpgPx6whniTC0Wwz6BcKN4voqsT7PvvwX/LD
PQhB05Nlcdf9hoM2jfQ63bCyZadDA4uByNHL1JL35EV1Z6G61TVsAY1l/M5FjYAt
GP6/4CHunAHDBFhiG0CyeDafH3gioqo8Bp0bOUmspeSLKFrwbEkrxjkymwARAQAB
tFBWYWxhbWlzIFZ1bG5lcmFiaWxpdHkgRGlzY2xvc3VyZSBQb2xpY3kgKFN0b3Jl
ZCBpbiBWYXVsdCkgPHNlY3VyaXR5QHZhbGFtaXMuY29tPokCVAQTAQgAPhYhBJsZ
fxiKQeuc9zRgoooGSefqyjE4BQJkf4YCAhsDBQkImF/JBQsJCAcCBhUKCQgLAgQW
AgMBAh4BAheAAAoJEIoGSefqyjE42GYQAJdn/ux2I5tWoYwfM5ZUU4P6fUTBe5Hm
AEaLbNe17y3y6gtIxW5TR3v4JXUIBtySIz/M03mdtSPLyLWb4+vdaaRJhyr2AV+l
jlXLP3EfAzQxG0Ff4T+/3IuDFWlceedvDj97uuiHFPEezXcZmd44/OjTvRmEobiM
n6iOEyUmUHiQwbYVwNBGM9Zuy4TBdQI1qc3dbj6p5333LkKHfO7ZuuvboZzoZKsK
Qqm257e7V/VPCxNv9IoTl+yqcIHSGg/FBnN5mKig1FPe08MQNjrBx5u0GYxRipwU
cwlRGcqc2shCCutcaxzoouiuNJ+r0BKBGG6OL/5ILoTPJL9yGqHFZtfHNQ7HAUWi
BetDpAT0ne0WNd3ajD6SiagRXHvofxtTv6hMnS/pt13h3sC6qLBPrm1PFHeQU+uG
TWLxr0RetNS/57E9ko6uJo3jXZZjoc4xlW+MTE64OvmzUvpAHd6icdeFLng8sHKi
FyCua3AsiXvkBBkUZw5cqfUaFucfYdXIuGA5NeeD8BFL6TUDvJ3kh8SNSvtMKDds
UZ1yQL36F0U7Rxv7RrwTBiwOMLSoCUWuaR8yGTs52sHLvjB/LMQ8W1n96ph7Ixbc
wmkU8ucSCuFDCPVOt7r6a4QZ5EAIwkr9WNrlcyubiMniyX2Gda5MLtVPFe8+KPgE
TFrWe3Nf+zv9uQINBGR/hgIBEADZrnZmt7wMhyBVqHFVoNlZ73/FCPsu6WXPb4nG
gTTTrpTVOHgI/ETa2u7hZLk8b27c6cPtHIqAUXTke0kBsBljRaBM01zNuYFxC7PZ
HU+4ojAXA6hUfaeSW5tOpb7OVqRPm6k+NFr/DFZWrrquWrBoyuXWYUSsLXPVOJ3I
RtXZ1oJMWgk9Hf7UC8iw6bbPi5/JJ2QW+SRMAj02emAwD2TCXGe7RuiyghiYOz/q
RO65oSTwyDlN7Tvb6ibdl9XDmNdSYC729Eewq7EwP07acLdvaSx5F81qf6wH2ZFW
HT21ZHnWE5uptcc+JOS4IW7i9fP6G1EgJ5hZ+ke0WoPrJY1qQGztt6FMv4R6ffll
kAOWKllA2kRnMMTVkXvP4bXilS0UXEfZ4yhOeYFxrekB0CpY3y9XarBWu0MilCFW
pu3h8AurkGqA67hVFJjJF5y/FcsW7YaZKAOBGYoKuTa0hvhEYDx+S+pdmd4fiLrS
4Ph/7sn+KU5iBR1hwvkr8iliO/16OPETKpXsHE5S0NEhyeA2FykARS5v4Z9WZwms
x5oRH89h6tKlESi6lZqqA7YCLROPMwcsf97elmqrRo5O2AqUkgjK7K/GCvP91dOL
8eFl0LrsXItO38j3cSQvnwOZWzDbBhtROes7tUitULovuPhbLo/BhvmIsjW9eKoB
Vw4OtwARAQABiQI8BBgBCAAmFiEEmxl/GIpB65z3NGCiigZJ5+rKMTgFAmR/hgIC
GwwFCQiYX8kACgkQigZJ5+rKMTjuUg/+PT2F53Rlkha2egYuaSSbXzMwvSBU/9Oi
p1Jm8KGQ0VA2hExgoOAx55yNcMj+X/cohz+65LgAOaA2oyqgoQG5i9fAprObbqEm
TLdQ4k7d3FkJSJc0K2pNhifdz3o9YSltv8vgdlDJvOxzcXmyVoC/T2zgJdHpy/XB
9fhRgZX+R/GRt59iDoUM693JN8fdEvKTbJkhqQYCI4rmoBhjJwxm8z8N0ub4nRB6
aceNe+w1FHszD4TRxAP3rpieU1XhTvxSWq+qMWMcN/T4firRnlYTQDS8FHUWGGyr
QjhECQSXccSvuX2mhpizciUfdodnCBaNO7ZfPOx2el4X5MWJcc1JJaDtVneDTmEM
sv3EhjvS/+WiyG91oB4nZ4HIoqwRIMViml5dxoiIyo+k0zaVd0WqCl3wJOX7f7xz
j5bPLEHbVyDJ7I+xUD8c958b1X3ayQxOquY5P/1YfJA6yBOvSbOUDYjouZGPk4JK
fNCr9KpZg7CxpN4c7uhfuFZpb5DqVIaqBHfhgDlEID7TmRBJbakvQLaNtez4ZNoG
1vpI56vVAuLmS/AbIbAdhUoKd/AJRcUVrSgfII13qQmHEmrlm0+IoMtAQbShqc1t
/s1bZ43mCvDrI+yBJg8JHumE2ullzOcYyVI11Wsy4s1Ei1hbrfa/c+GFdI9Zk1hA
6vGzTy3zjwc=
=tlf2
-----END PGP PUBLIC KEY BLOCK-----