Product security
Report a security vulnerability
At Gunnebo Safe Storage, we are committed to continuously improving the security of our products and digital solutions. As our portfolio evolves to include connected and digitally enabled solutions, safeguarding our customers against cybersecurity risks is a top priority. Security researchers, customers, and suppliers may report potential vulnerabilities in our products. This page outlines how to report a vulnerability and what to expect from us throughout the process.
For security vulnerabilities affecting Gunnebo’s IT estate, gunnebo.com, or other internet-facing services, please refer to our Coordinated Vulnerability Disclosure (CVD) page and use the reporting process described there.
Scope and responsible disclosure
This process applies primarily to products with digital elements and digital solutions that are supported and maintained by Gunnebo Safe Storage. Submission of a report does not create any contractual relationship, entitlement to compensation, or obligation on our part to implement a specific remediation measure or disclosure approach. We will not pursue legal action solely on the basis of good-faith security research conducted in accordance with these guidelines and applicable law.
Choose your reporting route
How to report a vulnerability
This reporting channel is intended for reporting vulnerabilities affecting products with digital elements and related product security concerns. If you believe you have discovered a security vulnerability in those products, please use the appropriate form below to report potential product security vulnerabilities based on your role. Personal data submitted through a vulnerability report will be processed in accordance with our Privacy Notice.
Supplier report
Report a potential vulnerability in a product, component, service or technology supplied to Gunnebo Safe Storage.
Customer or researcher report
Report a potential vulnerability in a Gunnebo product or related digital service as a customer, researcher, partner or other external party.
Responsible disclosure guidelines
We kindly ask that reporters:
Investigation period
Allow us a reasonable period to investigate and remediate the issue before any public disclosure.
Responsible testing
Avoid exploiting the vulnerability beyond what is necessary to demonstrate it
Data protection
Do not access, modify or delete data belonging to others.
Direct reporting
Contact us directly through the appropriate reporting form.
Response process
What happens after you submit a report
We follow coordinated vulnerability disclosure principles. The exact process and timing may vary depending on the nature and complexity of the issue, but it will normally include the following stages:
01
Submission received
We aim to acknowledge receipt of vulnerability reports within a reasonable timeframe.
02
Initial assessment
We review the information and may request further details. Where required, we comply with applicable regulatory reporting obligations
03
Investigation and action
We investigate the issue and determine the appropriate remediation or mitigation.
04
Coordinated communication
Where relevant, we coordinate remediation and disclosure with the reporter.
Information submitted through this process may be shared within the Gunnebo Safe Storage businesses and with relevant service providers, suppliers, regulators or authorities where necessary to investigate, mitigate or comply with applicable legal obligations.
Contact
General product security enquiries
For enquiries that are not related to a digital product vulnerability report, please use the general contact page.






















