Vulnerability Disclosure
Exertus values the contribution of security researchers and others who help us identify and address potential security weaknesses. We encourage responsible reporting and aim to work constructively with anyone who submits a vulnerability report in good faith.
What can you report
This disclosure process covers vulnerabilities affecting:
- Exertus products and solutions
- The Exertus public website at exertus.fi
- Customer-facing digital services and channels operated by Exertus
Vulnerabilities affecting third-party services or products that are not controlled by Exertus should be reported directly to the relevant provider.
How to contact us
Send vulnerability reports to the Exertus Product Security Incident Response Team (PSIRT): security@exertus.fi
Please submit reports in English.
What to include
Provide the following information where possible:
- The affected product, version, service, or URL
- A clear technical description of the vulnerability
- Steps required to reproduce the issue
- The potential security impact
- Supporting evidence, such as screenshots, logs, network captures, or proof-of-concept code
- Whether the vulnerability has already been reported or published elsewhere
- Your contact details, unless you wish to remain anonymous
- Whether and how you would like to be credited
Please do not include personal data, credentials, confidential customer information, or other sensitive information unless it is necessary to explain the vulnerability.
Process
We will acknowledge your report, assess the information provided, and contact you if additional details are required. For confirmed vulnerabilities, we will coordinate remediation and any appropriate disclosure.
Reports and reporter information will be handled confidentially, subject to applicable legal requirements.
Exertus does not intend to pursue legal action against researchers whose activities are conducted in good faith and comply with this policy.
Thank you for helping us improve the security of Exertus products and services.
Policy updates
This policy may be updated periodically. The current version is always available at: Vulnerability Disclosure page