CVD Policy
Coordinated Vulnerability Handling and Disclosure Policy | Prodrive Technologies
Effective as of: 8 August 2026
Prodrive Technologies is committed to supporting the safety and security of users of its products. We follow a holistic and comprehensive approach to secure its products, solutions, services, and IT infrastructure. Prodrive Technologies has formalized a process for handling reported security vulnerabilities in its product portfolio and IT infrastructure.
Prodrive Technologies is prepared to work in good faith with individuals that inform us of vulnerabilities. Prodrive Technologies openly accept reports for currently listed Prodrive Technologies products, solutions. Prodrive Technologies does not intend to engage in legal action against individuals who:
Engage in testing of systems/research without harming anyone and not result in Denial of Service.
Test on products without affecting customers, or receive permission/consent from customers before engaging in vulnerability testing against their devices/software, etc.
Adhere to the applicable laws.
Perform coordinated disclosure, i.e. refrain from disclosing vulnerability details to the public before a mutually agreed-upon timeframe expires.
Avoid impact on the safety or privacy of anyone.
Any use of a discovered vulnerability must be limited to activities necessary for its identification and verification. Accessing, downloading, modifying, or deleting data beyond what is required for this purpose is not permitted.
Prodrive Technologies does not operate a bug bounty or financial reward program. Submission of a vulnerability report does not create an entitlement to compensation, reimbursement, or reward. Prodrive Technologies nevertheless appreciates responsible disclosure and values contributions from the security research community.
The vulnerability handling process consists of the following four steps at Prodrive Technologies:
Report
To report a security vulnerability affecting a Prodrive Technologies product, use the contact details provided in the Vulnerability Contact Information section. Include the information listed below to help us assess and reproduce vulnerability. Prodrive Technologies usually acknowledges vulnerability reports within one business day.
Please report the following information:
Description of vulnerability, including proof-of-concept exploit code or network traces (if available)
Affected product, including model and firmware version (if available)
Publicity of vulnerability (was it already publicly disclosed?)
Possible mitigations and recommendations
Everyone is encouraged to report discovered vulnerabilities, regardless of service contracts or product lifecycle status. Prodrive Technologies welcomes vulnerability reports from researchers, industry groups, CERTs, partners and any other source as it does not require a nondisclosure agreement as a prerequisite for receiving reports. Prodrive Technologies respects the interests of the reporting party (also anonymous reports if requested) and agrees to handle any vulnerability that is reasonably believed to be related to Prodrive Technologies products.
Prodrive Technologies urges reporting parties to perform a coordinated disclosure, as immediate public disclosure causes a ‘0-day situation’ which puts Prodrive Technologies and its customers’ systems at unnecessary risk.
Analysis
Prodrive Technologies investigates and reproduces vulnerability. If needed, Prodrive Technologies will request more information from the reporter.
Handling
Prodrive Technologies performs internal vulnerability handling in collaboration with the responsible teams. Regular communication is maintained between Prodrive Technologies and the reporting party to inform about the current status and to ensure that the vendor’s position is understood by the reporting party. If available, pre-releases of software fixes may be provided to the reporting party for verification.
Disclosure
After the issue was successfully analyzed and if a fix is necessary to cope with the vulnerability, corresponding fixes will be developed and prepared for distribution. Prodrive Technologies will use existing customer notification processes to manage the release of patches.
Customer notification usually contains the following information:
Description of the vulnerability with CVE reference and CVSS score
Identity of known affected products and software/hardware versions
Information on mitigating factors and workarounds
The location of available fixes
Vulnerability Contact Information
Prodrive Technologies CSIRT / PSIRT
Contact for vulnerability reporting on products, solution and services