security

CVD Policy of the Sisag Group

1 Reporting Vulnerabilities

The security of our products, systems and online services is a high priority for the Sisag Group ("we", "us" or "our"). If you discover a potential vulnerability, we encourage you to report it to us. All reports will be carefully reviewed.

 

Contact

Email: security@sharecomm.ch
Languages: German or English 

 

To enable us to process your report efficiently, please provide the following information where possible:

  • affected product or system, including version information
  • description of the vulnerability
  • steps to reproduce the vulnerability
  • assessment of the potential impact
  • information on whether, to your knowledge, the vulnerability is already being actively exploited

We will acknowledge receipt of your report within five business days and provide you with an initial assessment within 15 business days. We carefully review every report, keep you informed about its status and coordinate the timing of any disclosure with you.

The Sisag Group does not operate a bug bounty programme. No financial compensation is provided for reporting vulnerabilities.

2 Scope

This CVD Policy applies to all products, systems, online services and websites operated by the Sisag Group. The Sisag Group comprises the following companies:

  • Sisag Holding AG (CHE-105.738.585)
  • Sisag AG (CHE-490-116.653), www.sisag.ch
  • Remec AG (CHE-115-4664-283), www.remec.ch
  • sharecomm ag (CHE-105.658.549), www.sharecomm.ch
  • SisCampus AG (CHE-266.167.011), www.54-hochgenuss.ch
  • sisware ag (CHE-222.389.799)

Vulnerability reports are received and coordinated centrally across the Group. As a general rule, the Sisag Group company operating the affected product, system, online service or website is responsible for further handling the report.

3 Responsible Vulnerability Reporting

The following principles apply to responsible vulnerability reporting:

  • Limit your testing to what is necessary to demonstrate the vulnerability. Do not copy, modify or delete data belonging to others. If you are able to access sensitive or personal data, stop your investigation and inform us immediately.
  • Do not perform tests on our customers' production systems or installations. Our systems are used in safety-critical environments. Interference with systems in operation may endanger the safety of individuals.
  • Social engineering, physical attacks and denial-of-service testing are not permitted.
  • Treat information about a vulnerability as confidential until it has been remediated and any disclosure has been coordinated with us.

4 Safe Harbor

If you discover a potential security vulnerability and report it in accordance with this Policy, we will consider your actions to have been responsible and carried out in good faith. Provided that you comply with the requirements of this Policy, we will generally not initiate criminal or civil proceedings against you. This does not apply to actions that go beyond the scope described in this Policy or that intentionally cause damage.

5 Coordinated Vulnerability Disclosure

We aim to remediate reported vulnerabilities within 90 days of receiving the report. Where remediation requires coordination with system operators, manufacturers or suppliers, this period may be extended. In such cases, we will inform the reporting person of the reasons and provide an updated timeline. Where appropriate, we publish a Security Advisory for remediated vulnerabilities.

6 Handling of Your Personal Data

We use the information you provide to assess and remediate the reported vulnerability, to communicate with you and to comply with legal reporting obligations. We will not disclose your name or other personal information to third parties without your consent unless we are legally required to do so.

Further information on how we process personal data can be found in our Privacy Policy.

7 Vulnerabilities in Third-Party Products

If a reported vulnerability affects a third-party component or an open-source product used by us, we will, where necessary, coordinate its handling with the relevant manufacturer, provider or responsible open-source project.