1. Procedure
HeadSpin maintains a coordinated vulnerability disclosure process for receiving, assessing, investigating, and remediating reported security vulnerabilities in its products and services. Vulnerability reports submitted through approved channels are reviewed by the Product Security Team and managed through to resolution, customer notification, and coordinated disclosure where applicable. This policy supports HeadSpin’s compliance with applicable cybersecurity and vulnerability handling requirements, including the EU Cyber Resilience Act (CRA).
1.1 Scope
This policy applies to:
- All commercially distributed HeadSpin software products deployed for our EU customers.
- Publicly accessible web applications, portals, APIs, and online services operated under:
The following activities are not authorized under this policy:
- Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks
- Physical attacks against HeadSpin facilities, data centers, or offices
- Social engineering, phishing, impersonation, or similar attacks targeting employees, contractors, customers, or suppliers
- Unauthorized access, modification, deletion, or disclosure of customer, employee, or third-party data
- Introduction of malware, ransomware, or malicious code
- Automated scanning activities that may adversely affect service availability
- Testing against customer-owned or customer-hosted environments without explicit authorization
1.2 Reporting a Vulnerability
If you believe you have discovered a security vulnerability, please submit a report to:
Email: productsecurity@headspin.io
Where possible, please include the following information:
Required Information
Product or Asset Information
- Product name
- URL, API endpoint, or affected component
Vulnerability Description
- Vulnerability type (e.g., SQL Injection, Cross-Site Scripting, Remote Code Execution, Authentication Bypass, Privilege Escalation)
- Technical description of the issue
Reproduction Steps
- Clear, sequential instructions
- Required configuration or prerequisites
- Proof-of-concept code, scripts, screenshots, or logs where appropriate
Security Impact
- Potential impact on confidentiality, integrity, or availability
- Estimated severity or business impact, if known
Researcher Contact Information
- Name or preferred alias
- Email address for follow-up communication
1.3 Vulnerability Handling Process
Upon receipt of a vulnerability report, HeadSpin will:
- Log and acknowledge the report.
- Assess whether the report is within scope.
- Validate and reproduce the reported vulnerability.
- Perform risk and severity assessment using industry-standard methodologies, including CVSS where applicable.
- Assign the issue to the appropriate product engineering team.
- Develop and test corrective actions, mitigations, or workarounds.
- Coordinate remediation, customer communications, and release activities.
- Issue security advisories where appropriate.
All reports will be handled confidentially and on a best-effort basis.
1.4 Response Targets
HeadSpin aims to meet the following service targets:
| Activity |
Target Timeline |
| 1Acknowledgement of report |
Within 48 business hours |
| 2Initial triage and validation update |
Within 5 business days |
| 3Vulnerability severity assessment |
As part of validation process |
| 4Remediation planning |
Following successful validation |
| 5Ongoing status updates |
Periodically during investigation and remediation |
Actual remediation timelines may vary depending on:
- Severity of the vulnerability
- Product complexity
- Availability of corrective measures
- Impact on customers and production environments
1.5 Researcher Guidelines
Researchers are expected to:
- Act in good faith.
- Avoid privacy violations.
- Avoid accessing, modifying, destroying, or exfiltrating data.
- Avoid disruption of services or customer environments.
- Limit testing to the minimum necessary to demonstrate the vulnerability.
- Report vulnerabilities promptly after discovery.
- Maintain confidentiality until coordinated disclosure is agreed.
Researchers must immediately cease testing and notify HeadSpin if customer data, personal data, or sensitive information is inadvertently accessed.
1.6 Safe Harbor
HeadSpin will consider activities conducted in accordance with this policy to be authorized.
HeadSpin will not pursue legal action against security researchers who:
- Act in good faith;
- Comply with this policy;
- Respect privacy and confidentiality;
- Avoid service disruption or damage;
- Promptly report discovered vulnerabilities.
This Safe Harbor does not apply to activities that:
- Violate applicable laws or regulations;
- Involve unauthorized access to customer environments;
- Cause harm, disruption, or data loss;
- Exceed the scope of testing reasonably required to identify and validate a vulnerability.
1.7 Customer Advisories and Coordinated Disclosure
Where a reported vulnerability is validated, HeadSpin may:
- Develop a security patch or mitigation;
- Notify affected customers;
- Publish a security advisory;
- Coordinate public disclosure with the reporting researcher.
Public disclosure will normally occur only after:
- A corrective measure, mitigation, or workaround is available; or
- A reasonable remediation period has elapsed and affected parties have been informed.
1.8 Privacy
Personal information submitted as part of a vulnerability report will be processed solely for the purposes of investigating, managing, and resolving the reported security issue and in accordance with applicable data protection laws.
1.9 Contact Information
Product Security Team
Email: productsecurity@headspin.io
General Customer Support
Existing customers may continue to report product issues and vulnerabilities through their established support channels and customer Ticketing portal.