We read every report and aim to acknowledge receipt within 24 hours. Vulnerability information is sensitive, so we ask that you encrypt anything containing technical detail using our OpenPGP key.
Pick the option that fits and we will take you straight to the right form. If neither fits, or you would rather not use a form, email security@gaisler.com.
Vulnerability information is normally very sensitive. Because of that, Frontgrade Gaisler strongly encourages all potential security vulnerability reports sent by email to be encrypted using our OpenPGP PGP/GPG key.
E0F8 CA76 89E7 E683 85FD 93E6 D956 8B0C 1D02 8334
Form 1: I found a vulnerability in a Gaisler product
Use this form for a potential or confirmed security vulnerability affecting a Frontgrade Gaisler AB product or service. If you would rather send an encrypted report, email security@gaisler.com using our OpenPGP key.
Form 2: I have another security issue to report
Use this form for all other types of security issues and incidents: suspicious activity involving Gaisler systems or staff, phishing that appears to come from us, or any security concern that does not relate to a specific product.
Once a new vulnerability or other security issue is reported to us, this is the process we follow.
We confirm receipt of the reported issue without undue delay.
We assess and triage the reported issue within 24 hours to establish whether there is an issue.
We contact you, where possible and if needed, to request additional information or clarification.
If the vulnerability is confirmed, we develop and provide appropriate mitigation measures or security updates.
For reports impacting the EU Cyber Resilience Act (CRA), we make an initial report to the appropriate authority. In the case of anonymous reports, statutory response timelines under the CRA may not apply.
Once a solution is available, whether a fix or a mitigation, Gaisler will communicate back to the submitter and to others where appropriate. Public security advisories and bulletins are published on the Gaisler website.
Gaisler is committed to working with the reporter of the vulnerability to establish what can be a responsible disclosure by the reporter, and to coordinating disclosure where applicable.
We handle all vulnerability reports in good faith and ask reporters to act responsibly. In particular, reporters should refrain from exploiting vulnerabilities beyond what is necessary to demonstrate their existence.
Our security contact details are also published in machine-readable form at gaisler.com/.well-known/security.txt, following RFC 9116.