
Product Security
Laetus supports the responsible reporting of product security vulnerabilities. Our Product Security Incident Response Team (PSIRT) is the central point of contact for reports of potential vulnerabilities in Laetus products, software solutions, and related digital components.
Report Vulnerabilities
If you have discovered a potential security vulnerability in a Laetus product, please send as complete a description as possible to our PSIRT: psirt@laetus.com
PGP Public Key: Download Public Key
Please do not submit any passwords, personal data, live customer data, or other confidential information unless it is absolutely necessary for analyzing the vulnerability.
What information do we need?
The more detailed the report, the faster we can conduct the technical evaluation.
Please provide the following information if possible:
Product Information
- Product Name or Product Family
- Software, Firmware, or Hardware Version
- Configuration and Operating Environment
- Affected Component or Function
Technical Description
- Brief Description of the Vulnerability
- Expected and Actual Behavior
- Steps to Reproduce
- Potential Impact
Evidence
- Screenshots, logs, or traces
- Proof-of-concept, if available
- Date and nature of the discovery
- Contact information for inquiries
Our Approach
Upon receiving a report, the Laetus PSIRT coordinates further handling
with the relevant product, development, quality, and security contacts.
| 1 | Confirm Receipt | We acknowledge receipt of the report and determine whether additional information is needed. |
| 2 | Analyze | The reported vulnerability is technically assessed, reproduced, and classified based on its potential impact. |
| 3 | Resolve | Any necessary corrective actions, mitigations, or security updates are coordinated with the relevant teams. |
| 4 | Communicate | We keep the reporter appropriately informed of progress and publish security advisories as needed. |
Responsible Disclosure
We ask that you report vulnerabilities responsibly and give Laetus sufficient opportunity to analyze and resolve them before sharing any information publicly.
As part of responsible disclosure, we ask that you:
- Do not disrupt production systems, customer systems, or business operations.
- Do not view, modify, or delete any data that is not necessary to verify the vulnerability.
- Do not publicly disclose vulnerabilities before Laetus has had sufficient opportunity to evaluate the report and prepare appropriate countermeasures.
Not to be used for Support Cases
This reporting channel is intended exclusively for product safety issues. General technical support requests, spare parts requests, service cases, or commercial inquiries should be submitted through the regular Laetus service and contact channels.
If you would like to contact our service department, you can do so at service@laetus.com.