Purpose
We are committed to product security and user trust. This page describes how we receive, assess, remediate, and disclose security vulnerabilities in our products, and explains our process so that reporters know what to expect.
Scope
This policy covers security vulnerability reports for our NGFW product line and associated firmware.
In scope — Reports that may affect the Confidentiality, Integrity, or Availability (CIA) of a product without authorization, including but not limited to: unauthorized access, privilege escalation, remote code execution, information disclosure, authentication bypass, denial of service, or other exploitable security risks.
Out of scope — General product usage, feature requests, or non-security issues, including:
- Feature requests, enhancement suggestions, or UI/UX feedback
- Specification differences or behaviors that do not pose a security risk
- Compatibility, interoperability, or deployment environment constraints
- Performance issues or documentation corrections
- Security best-practice suggestions without a demonstrable exploit
- General technical support, configuration assistance, or troubleshooting requests
Reports that fall out of scope may be redirected to the appropriate support channel after initial review.
Vulnerability Handling Process
We follow a structured process to ensure every report is properly assessed and addressed.
Phase 1
Phase 2
Phase 3
Phase 4
Phase 5
- Intake and Discovery: Reporter submits the security issue and supporting technical details via the Vulnerability Report Form.
- Triage: We confirm whether the report falls within the scope of product security and complete a preliminary data review.
- Verification and Assessment: We attempt to reproduce the issue and assess its impact and severity.
- Remediation: We develop and internally validate a fix to ensure it is correct and stable.
- Security Advisory: Once remediation is complete, we publish a formal advisory via our Security Advisories page.
Our Commitments
We handle all security reports responsibly and in good faith, guided by the following principles:
- Every report is taken seriously and handled appropriately.
- Public disclosure occurs only after a fix has been developed and validated.
- We maintain necessary communication with reporters throughout the process.
- User safety and product stability are our top priorities.
- We apply a 90-day embargo period to minimize risk before a patch is available.
We encourage the security research community to support product security through responsible disclosure.
Report a Vulnerability
If you have discovered a potential security issue affecting our products, please submit your report via the following link: Vulnerability Report Form
Acknowledgements
We appreciate the contributions of security researchers, customers, and partners who help identify product security issues. Your efforts make a meaningful difference to the security of our products and the broader community.