Disclosure Policy - Check Point Research

Disclosure Policy

Check Point Research Coordinated Disclosure Procedure

As part of the activities performed by Check Point Research (CPR), we occasionally obtain information regarding security vulnerabilities in third party products/software.

In such cases, our main concern is to report these vulnerabilities to the affected parties and assist in the creation of a fix.

We also believe it is our professional and social responsibility to share these security vulnerabilities with the public to raise awareness, and to assist developers, vendors, and members of the security community to defend against this threat and/or to provide effective mitigations.

Check Point Research will perform any necessary actions to provide the affected vendors/software with the necessary information required to effectively address this issue within a reasonable timeframe prior to public disclosure.

This policy outlines the actions and procedures followed by Check Point Research to responsibly disclose these vulnerabilities:

No further deadline extensions will be given under any circumstances.

The above procedure does not limit or prevent Check Point from releasing the information into our product lines (such as signatures), at any point from the initial date of discovery, in order to protect our customers.

Upon public disclosure, Check Point Research will provide the summary of the disclosure timeline and communications with the affected parties.

Check Point Research will formally and publicly release security disclosures on our official CPR-Zero web site. Only entries listed on the web site should be considered official Check Point Research disclosures.