Purpose

Glaston is committed to maintaining the security of its products and services. We welcome reports of potential cybersecurity vulnerabilities from customers, researchers, suppliers and other parties and will investigate and address valid reports in a timely manner.

Reporting a Vulnerability

If you believe you have identified a security vulnerability affecting a Glaston product or service, please report it to:

Email
: psirt@glaston.net

Please include, where available:

  • Description of the vulnerability
  • Affected product and version
  • Steps to reproduce the issue
  • Potential impact
  • Supporting evidence or logs
  • Your contact details

Our Commitment

Upon receiving a vulnerability report, Glaston will:

  • Assess and investigate the reported issue.
  • Communicate with the reporter where appropriate.
  • Take reasonable measures to remediate confirmed vulnerabilities.
  • Coordinate public disclosure where appropriate after a mitigation or fix is available.

Responsible Disclosure

We ask reporters to:

  • Act in good faith.
  • Avoid actions that could disrupt services, compromise data or affect customers.
  • Do not test customer environments or third-party systems without explicit authorization.
  • Refrain from publicly disclosing the vulnerability until Glaston has had a reasonable opportunity to investigate and address it.

This policy applies to Glaston products, software and digital services owned or provided by Glaston.

Policy Updates

Glaston may update this policy periodically to reflect changes in its products, services or legal requirements.

Last updated: September 2026