Geltungsbereich
Diese Policy gilt für Smartpolice (alle Module und Komponenten) sowie von futureLAB betriebene Zusatzdienste.
Nicht abgedeckt ist Infrastruktur, die ausschliesslich durch Kunden selbst betrieben oder konfiguriert wird und nicht Bestandteil der von futureLAB gelieferten Software ist.
Was Sie uns mitteilen sollten
Betroffenes Modul/Version, Beschreibung der Schwachstelle und ihrer Auswirkung, Schritte zur Reproduktion (falls vorhanden), sowie ob die Schwachstelle bereits aktiv ausgenutzt wird oder öffentlich bekannt ist.
Verhaltensregeln für Meldende
Kein Zugriff auf echte Kundendaten oder Produktivsysteme über das zur Bestätigung notwendige Mass hinaus. Keine Denial-of-Service-Tests. Keine Veröffentlichung vor Abschluss der koordinierten Offenlegung. Meldung ausschliesslich über den oben genannten Kanal.
Unser Ablauf
Wir bestätigen den Eingang Ihrer Meldung innerhalb einer Woche. Bei erkennbarer Dringlichkeit, insbesondere bei Hinweisen auf eine bereits aktiv ausgenutzte Schwachstelle, erfolgt eine erste Sichtung deutlich schneller. Nach der Bestätigung nehmen wir eine Einschätzung vor und informieren Sie über den weiteren Verlauf bis zur Behebung.
Koordinierte Offenlegung
Wir streben eine koordinierte Offenlegung innerhalb von 90 Tagen ab Meldung an. Bei komplexen Fällen ist eine Verlängerung nach Absprache möglich. Bei Hinweisen auf aktive Ausnutzung kann die Offenlegung in Abstimmung mit der meldenden Person beschleunigt werden.
Unsere Zusicherung (Safe Harbor)
Die rechtlich verbindliche Fassung dieser Zusicherung ist auf Englisch:
futureLAB AG welcomes the responsible reporting of potential security vulnerabilities.
futureLAB considers security research conducted in good faith and in accordance with this Policy to be authorised by futureLAB within the scope expressly defined in this Policy. futureLAB does not intend to initiate or support legal action against a security researcher solely in relation to such research, provided that the researcher:
- limits all testing to systems, services and environments that are expressly identified by futureLAB as being within the scope of this Policy;
- does not access or attempt to access systems, infrastructure or environments operated by or on behalf of futureLAB customers, including customer-operated Smartpolice installations, unless futureLAB has expressly authorised such testing in writing and has the legal authority to provide such authorisation;
- does not access, acquire, modify, delete, disclose, copy, transfer or retain personal data, customer data, evidence, case information or other confidential or sensitive information beyond what is strictly necessary to demonstrate the existence and security impact of a vulnerability;
- immediately stops testing and notifies futureLAB if customer data, personal data, evidence, case information or other sensitive or confidential information is encountered;
- does not disrupt, degrade, damage or otherwise adversely affect the availability, integrity, confidentiality or operation of any system, service or data;
- does not conduct denial-of-service or resource-exhaustion attacks, social engineering, phishing, physical attacks, credential attacks against third parties, or attacks against employees, customers, suppliers or other third parties;
- does not introduce malware, ransomware, backdoors, persistent access mechanisms or other malicious code;
- does not exploit a vulnerability beyond the minimum extent reasonably necessary to demonstrate its existence and security impact and does not use a vulnerability to pivot to, access or test other systems or accounts;
- does not download, extract or exfiltrate data except to the minimum extent strictly necessary to demonstrate the existence of a vulnerability;
- reports the vulnerability promptly to futureLAB through the designated security contact and provides sufficient information to allow futureLAB to reproduce, investigate and remediate the vulnerability;
- provides futureLAB with a reasonable opportunity to investigate and remediate the vulnerability before disclosing technical details to any third party or to the public; and
- does not use any vulnerability, access obtained or information acquired through the research for extortion, financial gain, competitive purposes, commercial exploitation or any unlawful purpose.
This Safe Harbor applies only to claims and rights that futureLAB AG has the legal authority to waive, authorise or refrain from enforcing. It does not provide authorisation on behalf of futureLAB customers, hosting providers, infrastructure providers, software vendors or any other third party. Nothing in this Policy prevents any such third party or any competent public authority from taking action.
Nothing in this Policy authorises conduct that is prohibited by applicable law.
Nothing in this Policy grants any licence, ownership interest or other intellectual property right in any software, source code, object code, documentation, data, database, trademark, trade secret or other intellectual property of futureLAB or any third party. In particular, this Policy does not authorise the researcher to reproduce, distribute, disclose, modify, create derivative works from, commercially exploit or otherwise use such intellectual property except to the limited extent strictly necessary to conduct security research expressly authorised under this Policy. Nothing in this paragraph is intended to restrict any right that cannot lawfully be excluded or restricted under applicable law.
Any authorisation provided under this Policy is limited solely to the security research expressly permitted by this Policy and does not constitute authorisation to access or use any other futureLAB or third-party system, service, account, data or infrastructure.
Where a researcher is uncertain whether a proposed activity falls within the scope of this Policy, the researcher should contact security@futurelab.ch and obtain written confirmation from futureLAB before proceeding.
This Policy does not constitute a bug bounty programme and does not create any entitlement to compensation, reward, reimbursement or other consideration.