Vulnerability reporting policy
SAM welcomes vulnerability reports on its products. This page sets out how to reach us, what we commit to, and what we expect in return.
Scope
This policy covers SAM TOOL MANAGER, the software running on SAM'URAI dispensing units, and SAM TOOL SUPERVISOR, the platform several unit functions depend on. Together they form a single product and fall under a single policy.
The corporate website, email and internal information systems of SAM are outside this policy. A report about them is still welcome at the same address and will be routed to the relevant team.
Reporting a vulnerability
Contact address : rssi@sam.eu
So we can triage quickly, please include where possible:
- the affected component and the version you observed;
- reproduction steps, as precise as possible;
- the impact you estimate, and what an attacker would gain;
- the prerequisites, in particular whether physical access to a unit or a valid account is required.
Please do not send personal or customer data with your report. If your proof of concept produced any, tell us rather than attaching it.
What we commit to
- Acknowledgement within 5 business days. If you have not heard back after that, chase us: assume the message was lost.
- Triage and a reasoned answer: we tell you whether we accept the report, and if not, why.
- Progress updates until the fix or the closure. We do not commit to a fixed remediation deadline in advance, but we tell you the course we have chosen and let you know if it changes.
- Credit on publication if you want it, under the name or handle of your choice.
What we ask of you
- Stay within good faith research: demonstrate the vulnerability, do not exploit it.
- Do not access, extract, alter or destroy data that is not yours. If you reach such data by accident, stop and tell us.
- Do not degrade the availability of the service or of a unit in service.
- Do not use social engineering against SAM employees, customers or contractors.
- Do not carry out a physical attack on a unit installed at a customer site.
- Allow us a reasonable delay before any publication. Our reference is 90 days from acknowledgement, adjustable by mutual agreement depending on severity and how hard the fix is.
Good faith research
We consider research carried out within the rules above to be authorised, and we will not pursue action against it. If a third party acts following a report that complies with this policy, we will make it known that the work was authorised. This undertaking does not cover acts outside that framework, nor anything the law places beyond the parties' disposal.
Publication of fixes
Fixed vulnerabilities are described in the release notes of the update that fixes them, with the affected component and the nature of the problem. We delay publication where it would put units not yet updated at more risk than silence.