Cross
ACE
New
CloudTest Lite
New
CloudTest Go
New
CloudTest Pro
New
Productsdown arrow
HeadSpin Platform
CloudTest Lite
New
CloudTest Go
New
CloudTest Pro
New
TEM
New
Accessibility Testing
New
Image Injection
New
Solutionsdown arrow
Mobile App TestingCross Browser TestingAV TestingDRM TestingPerformance TestingSmart TV TestingExperience & Performance MonitoringAppium & Selenium Test AutomationDeployment Models
Industriesdown arrow
TelcosMediaGamingBankingRetailDigital NativesAutomobileHealthcareTravel and Hospitality
Featuresdown arrow
Regression IntelligenceGrafana DashboardsWaterfall UIGlobal Device InfrastructureMini RemoteVMOS
Resourcesdown arrow
FAQsIntegrationsWebinars & EventsBlogsWhitepapersCase Studies
Companydown arrow
About HeadSpinPartnersCareersPress Resources
Pricing
Log inConnect Now
LoginBook Free Trial
SolutionsIntegrationsCommunityResources Company
Request Demo
Menu button
Connect Now
Platformdown arrow
ASPM
DevSecOps Orchestration
Continuous Compliance
Products
New
Solutions
Industries
Features
Resources
Company
Pricing
Partners
Companydown arrow
About Us
Partners
Log inConnect Now
HeadSpin Platform
Test, debug, and optimize digital experiences across real devices, networks, and locations.
Differentiating capabilities:
  • Real-device and browser testing
  • Global network and location coverage
  • 130+ performance KPIs
  • Regression detection across builds
  • Logs, session data, and RCA
  • Appium and Selenium support
ACE
ACE
New
AI that executes, validates, and self heals
cloudtest lite
CloudTest Lite
New
Affordable Real Device Testing for Emerging Teams
cloudtest go
CloudTest Go
New
Affordable Real Device Testing for Digital Enterprises
cloudtest pro
CloudTest Pro
New
The Ultimate Solution for a Powerful Blend of Functional & Performance Testing!
tem
TEM
New
Centralized mobile test execution in cloud
accessibility testing
Accessibility Testing
New
Enhance Your Accessibility Testing With HeadSpin
image injection
Image Injection
New
Automate camera-based testing

SUPPORT

faqs
FAQS
integrations
Integrations

RESOURCE CENTER

webinars & events
Webinars & Events
blogs
Blogs

‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎

case studies
Case Studies
whitepaper
Whitepapers

ABOUT US

About Headspin
About HeadSpin
Global Device Infrastructure
Partners

‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎

Careers
Careers

‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎

News
Press Resources

SOLUTIONS

mobile app tetsing
Mobile App Testing
smart tv testing
DRM Testing
experience monitoring
Experience & Performance Monitoring

‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎

cross browser testing
Cross Browser Testing
performance optimization
Performance Testing
appium - mobile test automation
Appium & Selenium Test Automation

‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎

appium - mobile test automation
AV Testing
smart tv testing
Smart TV Testing
smart tv testing
Deployment Models

INDUSTRIES

telcos
Telcos
banking
Banking
automobile
Automobile

‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎

gaming
Media
retail
Retail
retail
Healthcare

‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎

gaming
Gaming
digital natives
Digital Natives
experience monitoring
Travel and Hospitality

FEATURES

telcos
Regression Intelligence
global device infrastruture
Global Device Infrastructure

‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎

gaming
Grafana Dashboards
gaming
Mini Remote

‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎

gaming
Waterfall UI
gaming
VMOS

Coordinated Vulnerability Disclosure (CVD) Policy

1. Procedure

HeadSpin maintains a coordinated vulnerability disclosure process for receiving, assessing, investigating, and remediating reported security vulnerabilities in its products and services. Vulnerability reports submitted through approved channels are reviewed by the Product Security Team and managed through to resolution, customer notification, and coordinated disclosure where applicable. This policy supports HeadSpin’s compliance with applicable cybersecurity and vulnerability handling requirements, including the EU Cyber Resilience Act (CRA).

1.1 Scope

This policy applies to:

  • All commercially distributed HeadSpin software products deployed for our EU customers.
  • Publicly accessible web applications, portals, APIs, and online services operated under:
    • *.headspin.io

The following activities are not authorized under this policy:

  • Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks
  • Physical attacks against HeadSpin facilities, data centers, or offices
  • Social engineering, phishing, impersonation, or similar attacks targeting employees, contractors, customers, or suppliers
  • Unauthorized access, modification, deletion, or disclosure of customer, employee, or third-party data
  • Introduction of malware, ransomware, or malicious code
  • Automated scanning activities that may adversely affect service availability
  • Testing against customer-owned or customer-hosted environments without explicit authorization

1.2 Reporting a Vulnerability

If you believe you have discovered a security vulnerability, please submit a report to:

Click Here to Submit a Report

Email: productsecurity@headspin.io

Where possible, please include the following information:

Required Information

Product or Asset Information

  • Product name
  • URL, API endpoint, or affected component

Vulnerability Description

  • Vulnerability type (e.g., SQL Injection, Cross-Site Scripting, Remote Code Execution, Authentication Bypass, Privilege Escalation)
  • Technical description of the issue

Reproduction Steps

  • Clear, sequential instructions
  • Required configuration or prerequisites
  • Proof-of-concept code, scripts, screenshots, or logs where appropriate

Security Impact

  • Potential impact on confidentiality, integrity, or availability
  • Estimated severity or business impact, if known

Researcher Contact Information

  • Name or preferred alias
  • Email address for follow-up communication

1.3 Vulnerability Handling Process

Upon receipt of a vulnerability report, HeadSpin will:

  1. Log and acknowledge the report.
  2. Assess whether the report is within scope.
  3. Validate and reproduce the reported vulnerability.
  4. Perform risk and severity assessment using industry-standard methodologies, including CVSS where applicable.
  5. Assign the issue to the appropriate product engineering team.
  6. Develop and test corrective actions, mitigations, or workarounds.
  7. Coordinate remediation, customer communications, and release activities.
  8. Issue security advisories where appropriate.

All reports will be handled confidentially and on a best-effort basis.

1.4 Response Targets

HeadSpin aims to meet the following service targets:

Activity Target Timeline
1Acknowledgement of report Within 48 business hours
2Initial triage and validation update Within 5 business days
3Vulnerability severity assessment As part of validation process
4Remediation planning Following successful validation
5Ongoing status updates Periodically during investigation and remediation

Actual remediation timelines may vary depending on:

  • Severity of the vulnerability
  • Product complexity
  • Availability of corrective measures
  • Impact on customers and production environments

‍

1.5 Researcher Guidelines

Researchers are expected to:

  • Act in good faith.
  • Avoid privacy violations.
  • Avoid accessing, modifying, destroying, or exfiltrating data.
  • Avoid disruption of services or customer environments.
  • Limit testing to the minimum necessary to demonstrate the vulnerability.
  • Report vulnerabilities promptly after discovery.
  • Maintain confidentiality until coordinated disclosure is agreed.

Researchers must immediately cease testing and notify HeadSpin if customer data, personal data, or sensitive information is inadvertently accessed.

1.6  Safe Harbor

HeadSpin will consider activities conducted in accordance with this policy to be authorized.

HeadSpin will not pursue legal action against security researchers who:

  • Act in good faith;
  • Comply with this policy;
  • Respect privacy and confidentiality;
  • Avoid service disruption or damage;
  • Promptly report discovered vulnerabilities.

This Safe Harbor does not apply to activities that:

  • Violate applicable laws or regulations;
  • Involve unauthorized access to customer environments;
  • Cause harm, disruption, or data loss;
  • Exceed the scope of testing reasonably required to identify and validate a vulnerability.

1.7 Customer Advisories and Coordinated Disclosure

Where a reported vulnerability is validated, HeadSpin may:

  • Develop a security patch or mitigation;
  • Notify affected customers;
  • Publish a security advisory;
  • Coordinate public disclosure with the reporting researcher.

Public disclosure will normally occur only after:

  • A corrective measure, mitigation, or workaround is available; or
  • A reasonable remediation period has elapsed and affected parties have been informed.

1.8 Privacy

Personal information submitted as part of a vulnerability report will be processed solely for the purposes of investigating, managing, and resolving the reported security issue and in accordance with applicable data protection laws.

1.9 Contact Information

Product Security Team
Email: productsecurity@headspin.io

General Customer Support
Existing customers may continue to report product issues and vulnerabilities through their established support channels and customer Ticketing portal.

Copyright © 2021 HeadSpin, Inc. All Rights Reserved.‍
|  Cookies
Privacy
Terms
|  CVD Policy