Purpose

We are committed to product security and user trust. This page describes how we receive, assess, remediate, and disclose security vulnerabilities in our products, and explains our process so that reporters know what to expect.



Scope

This policy covers security vulnerability reports for our NGFW product line and associated firmware.


In scope — Reports that may affect the Confidentiality, Integrity, or Availability (CIA) of a product without authorization, including but not limited to: unauthorized access, privilege escalation, remote code execution, information disclosure, authentication bypass, denial of service, or other exploitable security risks.


Out of scope — General product usage, feature requests, or non-security issues, including:


Reports that fall out of scope may be redirected to the appropriate support channel after initial review.



Vulnerability Handling Process

We follow a structured process to ensure every report is properly assessed and addressed.


Phase 1

Intake and Discovery

Phase 2

Triage

Phase 3

Verification and Assessment

Phase 4

Remediation

Phase 5

Security Advisory

Phase 1

Intake and Discovery

Phase 2

Triage

Phase 3

Verification and Assessment

Phase 4

Remediation

Phase 5

Security Advisory





Our Commitments

We handle all security reports responsibly and in good faith, guided by the following principles:


We encourage the security research community to support product security through responsible disclosure.



Report a Vulnerability

If you have discovered a potential security issue affecting our products, please submit your report via the following link: Vulnerability Report Form



Acknowledgements

We appreciate the contributions of security researchers, customers, and partners who help identify product security issues. Your efforts make a meaningful difference to the security of our products and the broader community.