Responsible disclosure

Introduction

Securing the Siip identity infrastructure, including identity wallets, onboarding flows, and credential services, is our highest priority.

We value the efforts of security researchers and ethical hackers who help us identify and report these vulnerabilities in a responsible manner.

Scope

This policy applies to all systems and services of Siip Group and all its affiliated subsidiaries (hereinafter referred to as Siip) that process or store customer data or personal information.

Out of scope:
third-party systems, internal company systems that do not process customer data or personal information, and activities such as social engineering and denial-of-service testing.

What we expect from you

Participation in this policy program is permitted only on the condition that you:

Prohibited activities

The following activities are not permitted:

Safe Harbor

If you act in accordance with this policy:

This applies only if:

Termination of activities

We reserve the right to request that you cease your activities immediately if:

In that case, we expect you to cease all further activities immediately.

Handling of reports

Siip:

Legal framework

This policy has been drafted in accordance with applicable laws and regulations, including:

Activities outside the scope of this policy may lead to civil or criminal legal action.

Contact

Reports and all communication regarding this policy must be sent exclusively to responsibledisclosure@siip.group