The security of our products and solutions is of high importance to b-plus.
Customers, partners, security researchers, and other interested parties can report security vulnerabilities affecting b-plus products and solutions to our Product Security Incident Response Team (PSIRT).
This reporting channel is intended for vulnerabilities in b-plus products, software, firmware, cloud services, and other digital solutions. General support requests should be submitted through the appropriate support channels.
What information should be included?
To enable efficient processing of your report, please provide the following information whenever possible:
Our Handling Process
After receiving your report, our PSIRT will:
1. Acknowledge receipt of the report
2. Validate and analyze the reported vulnerability
3. Assess the potential impact and determine the appropriate priority
4. Develop and implement appropriate remediation or mitigation measures
5. Publish security information, updates, or fixes, where required
We kindly request that reported vulnerabilities are not publicly disclosed until b-plus has had the opportunity to analyze the issue and, where necessary, implement corrective measures. b-plus aims to follow a coordinated vulnerability disclosure approach in line with recognized industry best practice.
Confidentiality
Reported information will be treated confidentially and used solely for the analysis, assessment, remediation, and, where necessary, communication of security risks.
We appreciate the efforts of all individuals and organizations who contribute to improving the security of our products through responsible vulnerability reporting.