Sign in

Normet Security Vulnerability Reporting Policy and Good-Faith Expectations


1. Purpose

Normet welcomes good-faith reporting of security vulnerabilities and related cybersecurity deviations affecting Normet-controlled products, services, and public-facing resources.

This policy explains how to report a security issue to Normet, what kinds of activity Normet considers in scope for good-faith reporting, and how Normet coordinates handling of disclosures.
This Normet Coordinated Vulnerability Disclosure (CVD) policy is intended to be publicly available via an online resource such as a normet.com/security public-facing web page.

Most of Normet's public web resources also provide a /.well-known/security.txt file. This file helps security researchers find the correct reporting contact and the location of this policy, and may also help them identify public Normet resources that fall within this policy's scope (security.txt → normet.com/security → PSIRT intake mailbox/portal → triage workflow).

2. What To Report

You may report:

  • vulnerabilities in Normet products with digital elements
  • vulnerabilities in third-party components where the issue affects a Normet product
  • vulnerabilities or security deviations affecting Normet-controlled websites, domains, DNS configurations, certificates, email-security records, and other public networking infrastructure
  • vulnerabilities or security deviations affecting Normet-managed hosted environments and services within the agreed Normet operating scope
  • findings related to Normet products or components that are identified in customer solutions or customer environments, where the finding concerns the Normet product or component itself

If you are unsure whether an issue or resource is in scope, you may contact Normet for further clarification at security[at]normet.com.

3. Research Scope And Good-Faith Expectations

This policy is intended to support good-faith security research and reporting concerning Normet-controlled products, services, and public-facing assets. It describes the kinds of activity and targets for which Normet is prepared to receive reports and coordinate handling. It is not a general authorisation to test any environment in which Normet components may appear.

3.1 Scope

  • Normet-controlled public-facing products, services, and other assets described in this policy are the intended scope for good-faith reporting activity and testing under this policy.
  • Customer-owned or customer-managed environments are not in scope for testing under this policy, even where they use Normet products or components.
  • Normet does not provide permission to test any environment that belongs to a customer and cannot grant such permission on a customer's behalf.
  • Findings related to Normet products or components that are identified in customer-owned or customermanaged environments during authorised security audits may be reported to Normet.
  • Other third-party systems, services, or infrastructure that Normet does not control are not in scope for testing under this policy.

If a customer places a final product on the market that incorporates Normet components and/or software, the responsibility as the manufacturer of the final product remains with the customer.

Most of Normet's public web resources also provide a /.well-known/security.txt file. This file helps security researchers find the correct reporting contact and the location of this policy, and may also help them identify public Normet resources that fall within this policy's scope.

3.2 Good-Faith Reporting Expectations

Normet expects good-faith reporters to follow these expectations:

  • limit activity to what is necessary to identify and demonstrate the issue
  • limit demonstration of SQL injection or similar database access issues to non-sensitive proof, such as database version information, and do not read, tamper, or exfiltrate data, manipulate permissions, or perform similar actions
  • limit demonstration of remote code execution to non-persistent informational commands, such as date or an operating-system-version command
  • do not establish persistence or continued presence in any Normet system
  • do not exfiltrate, download, modify, delete, or otherwise access data beyond what is strictly necessary to demonstrate the issue
  • do not cause denial-of-service, service degradation, destructive effects, malware deployment, or extortion activity
  • do not attempt social engineering, phishing, physical intrusion, or credential theft
  • if planned activity is borderline or not clearly covered by these expectations, ask Normet for clarification before proceeding
  • do not disclose vulnerability information publicly or to other third parties before coordinated handling has progressed sufficiently, except where disclosure to Traficom / NCSC-FI, another CSIRT, ENISA, another competent authority, or disclosure required by law or safety reasons makes that necessary
  • do not report purely theoretical issues without a practical proof-of-concept showing real exploitability, such as clickjacking of non-actionable information sites or missing headers without practical consequences

These expectations do not grant a general authorisation for penetration testing or intrusive activity.
Normet does not operate a public bug bounty or reward program under this draft policy.

4. How To Report

Email address security[at]normet.com is Normet's primary contact point for coordinated vulnerability disclosure and does not rely exclusively on automated tools.

Disclosures may also be coordinated through a CSIRT, including Traficom / NCSC-FI where applicable. Where relevant, official coordination may also involve ENISA or another competent authority.

To help Normet assess the issue, include where possible:

  • affected product, service, URL, domain, component, or other asset
  • version information, environment details, or relevant identifiers
  • steps to reproduce
  • potential impact
  • logs, screenshots, proof-of-concept material, or other supporting evidence
  • your contact details

5. What Normet Commits To

Normet aims to:

  • provide a clear human-handled reporting path through security[at]normet.com
  • acknowledge receipt of good-faith reports within 3 business days
  • review and triage the report internally
  • request clarification if needed
  • route the matter to the correct internal handling process
  • coordinate handling in good faith with reporters acting within this policy before public disclosure where appropriate
  • validate and, where necessary, remediate vulnerabilities before detailed information is disclosed to third parties or to the public

Normet does not provide fixed remediation deadlines for reported security deviations, but it aims to act without undue delay in proportion to the risk level of the reported issue.

Normet does not provide internal details about the mitigation process for reported security deviations.

Where legal, regulatory, customer, or incident-response obligations apply, Normet may need to coordinate handling with other parties, including customers, component maintainers, NCSC-FI, other CSIRTs, ENISA, other competent authorities, or other responsible manufacturers.

Some disclosures may require confidential handling while validation, remediation, customer coordination, or official coordination is ongoing.

© 2026 Normet

Ver. 28754