Report a security vulnerability or incident

If you have found a security vulnerability in a Frontgrade Gaisler product or service, or you want to report any other security issue affecting us, this page tells you how to reach us and what will happen next.

We read every report and aim to acknowledge receipt within 24 hours. Vulnerability information is sensitive, so we ask that you encrypt anything containing technical detail using our OpenPGP key.

What are you reporting?

Pick the option that fits and we will take you straight to the right form. If neither fits, or you would rather not use a form, email security@gaisler.com.

Vulnerability information is normally very sensitive. Because of that, Frontgrade Gaisler strongly encourages all potential security vulnerability reports sent by email to be encrypted using our OpenPGP PGP/GPG key.

Send your report encrypted

Fingerprint

E0F8 CA76 89E7 E683 85FD 93E6 D956 8B0C 1D02 8334

Public key file

keys.openpgp.orgDownload our public key

Free software to read and write PGP/GPG encrypted messages

OpenPGPGnuPGGpg4win

Form 1: I found a vulnerability in a Gaisler product

Short problem description

Please describe

Please describe the potential vulnerability, including any related known exploits

Please describe

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Security vulnerability in a Gaisler product or service

Use this form for a potential or confirmed security vulnerability affecting a Frontgrade Gaisler AB product or service. If you would rather send an encrypted report, email security@gaisler.com using our OpenPGP key.

Form 2: I have another security issue to report

Any other security issue or incident

Use this form for all other types of security issues and incidents: suspicious activity involving Gaisler systems or staff, phishing that appears to come from us, or any security concern that does not relate to a specific product.

Approximately, or if known, exact time

This form does not collect your name or email address unless you enter them yourself. We confirm receipt without undue delay and assess your report within 24 hours.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

What happens with your report

Once a new vulnerability or other security issue is reported to us, this is the process we follow.

1. Acknowledgement

We confirm receipt of the reported issue without undue delay.

2. Assessment and triage

We assess and triage the reported issue within 24 hours to establish whether there is an issue.

3. Follow-up questions

We contact you, where possible and if needed, to request additional information or clarification.

4. Remediation

If the vulnerability is confirmed, we develop and provide appropriate mitigation measures or security updates.

For reports impacting the EU Cyber Resilience Act (CRA), we make an initial report to the appropriate authority. In the case of anonymous reports, statutory response timelines under the CRA may not apply.

5. Communication

Once a solution is available, whether a fix or a mitigation, Gaisler will communicate back to the submitter and to others where appropriate. Public security advisories and bulletins are published on the Gaisler website.

Gaisler is committed to working with the reporter of the vulnerability to establish what can be a responsible disclosure by the reporter, and to coordinating disclosure where applicable.

Guidelines for reporters

We handle all vulnerability reports in good faith and ask reporters to act responsibly. In particular, reporters should refrain from exploiting vulnerabilities beyond what is necessary to demonstrate their existence.

Please note the following

  • If a reporting entity does not respond to requests for technical or content-related clarification, our ability to process the report may be limited or, in some cases, not possible.
  • Anonymous reports may be processed only to a limited extent, as we may be unable to request additional information or clarification.

Machine-readable contact

Our security contact details are also published in machine-readable form at gaisler.com/.well-known/security.txt, following RFC 9116.

Contact us

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.