HMS places the utmost importance on the security of our products and systems, however, despite all the measures we take, it cannot be excluded that vulnerabilities persist. For this operation to take place in an organized and secure manner, we invite you to follow the rules on this page before reporting a vulnerability.
We recognize the valuable role of the digital security research community and we welcome investigator reports on potential vulnerabilities in our products and systems. We prefer to be informed as soon as possible so that we can take the necessary measures to protect our customers and strengthen the confidentiality, availability and integrity of our systems. If you have identified a vulnerability, we give you the opportunity to inform us responsibly.
This applies if you use an encrypted email to contact us. If you instead use the Report incident and vulnerability form you must full out all the required fields and we will have what we need.
This responsible disclosure program is not designed for complaints. The program is also not intended to:
For any questions relating to these topics and for any other questions, please see our contact page.
HMS Networks does not offer compensation for vulnerability discovery.
If your actions have not respected the rules set out above, HMS Networks reserves the right to take legal action.
If you believe that you have discovered a security issue with our products or services. please notify us as soon as possible using the following email hms-csrt@hms-networks.com.
The following public PGP key is available for encrypted communication:
Key ID: 3F982669
Key fingerprint: 9810 5448 5CC5 2102 07D8 A6EF 7DA2 7ECE 3F98 2669