Introduction
Securing the Siip identity infrastructure, including identity wallets, onboarding flows, and credential services, is our highest priority.
We value the efforts of security researchers and ethical hackers who help us identify and report these vulnerabilities in a responsible manner.
Scope
This policy applies to all systems and services of Siip Group and all its affiliated subsidiaries (hereinafter referred to as Siip) that process or store customer data or personal information.
Out of scope:
third-party systems, internal company systems that do not process customer data or personal information, and activities such as social engineering and denial-of-service testing.
What we expect from you
Participation in this policy program is permitted only on the condition that you:
- report vulnerabilities promptly via responsibledisclosure@siip.group
- provide sufficient information to reproduce the issue
- do not exploit vulnerabilities
- do not gain access to customer or third-party data
- limit your research to strictly necessary actions
- do not disclose the vulnerability publicly before it has been resolved
Prohibited activities
The following activities are not permitted:
- disrupting systems, services, monitoring, logging, or operational processes, including DoS/DDoS attacks
- generating large amounts of traffic or requests
- automated scanning without prior written consent from Siip
- brute-force attacks
- social engineering or phishing
- data exfiltration
- testing outside the scope defined in this policy
Safe Harbor
If you act in accordance with this policy:
- we will not take civil or criminal action
- we will treat your report confidentially and with appreciation
This applies only if:
- no damage is caused
- activities are proportional
- you stop activities immediately upon Siip's first request
Termination of activities
We reserve the right to request that you cease your activities immediately if:
- these are disruptive to Siip's systems, monitoring, or business operations
- these fall outside the scope defined in this policy
- these pose a risk to users or infrastructure
In that case, we expect you to cease all further activities immediately.
Handling of reports
Siip:
- confirms receipt of your report within 5 business days
- assesses and prioritizes the report based on severity and impact
- strives to resolve vulnerabilities as quickly as possible
- communicates exclusively in writing via responsibledisclosure@siip.group
Legal framework
This policy has been drafted in accordance with applicable laws and regulations, including:
- Regulation (EU) 2016/679 (GDPR)
- Criminal Code, Article 138ab et seq. (computer intrusion)
- Directive (EU) 2022/2555 (NIS2)
- Regulation (EU) 2019/881 (Cybersecurity Act)
Activities outside the scope of this policy may lead to civil or criminal legal action.
Contact
Reports and all communication regarding this policy must be sent exclusively to responsibledisclosure@siip.group