Vulnerability Disclosure Policy
Sweco takes the security of its systems, applications and data seriously. We appreciate responsible disclosure of potential security vulnerabilities by security researchers, customers and other third parties. If you believe you have found a security vulnerability in one of our systems or applications, please report it to us as soon as possible via: helpdesk.gisict@sweco.nl
What to include in your report
To help us investigate and resolve the issue efficiently, please include as much relevant information as possible, such as:
- A clear description of the vulnerability
- The affected system, application, URL or service
- Steps to reproduce the issue
- Any supporting evidence, such as screenshots, logs or proof-of-concept details
- Your contact details, if you would like us to follow up with you
Please do not include sensitive personal data, confidential customer data or unnecessary copies of production data in your report.
Responsible testing
When investigating or reporting a vulnerability, we ask you to act responsibly and avoid actions that could harm Sweco, our customers, users or systems.
Please do not:
- Access, modify, delete or copy data that does not belong to you
- Disrupt, degrade or interrupt our services
- Perform denial-of-service testing
- Use social engineering, phishing, physical attacks or malware
- Publicly disclose the vulnerability before we have had the opportunity to investigate and address it
If you accidentally access data that is not yours, please stop immediately and report this in your vulnerability disclosure.
Our handling of reports
After receiving your report, Sweco will review the information and assess the potential impact and severity of the vulnerability.
We aim to handle reports carefully and responsibly, and to take appropriate measures based on the nature and risk of the reported vulnerability.
Coordinated disclosure
We ask you not to publicly disclose the vulnerability until Sweco has completed its investigation and, where necessary, implemented appropriate remediation or mitigation measures.
Contact
Security vulnerability reports can be sent to: helpdesk.gisict@sweco.nl