Security
How to tell us something is wrong
If you have found a vulnerability, the reporting route and our response commitments are below. If you are evaluating us, so is an honest account of where our access exists.
- Acknowledged
- 1 business day
- Assessed
- Within 5 days
- Credit
- If you want it
Definition
How do I report a security vulnerability to CirculeID?
Email ceo@fistasolutions.com with "Security disclosure" as the subject and enough detail to reproduce the issue. We acknowledge within one business day and give an initial assessment within five, with a named contact who stays with the report until it is closed.
Please do not post it publicly first, and please do not test against other customers’ data. Beyond that we are not going to threaten researchers with legal language: a report made in good faith is a favour, and we will treat it as one.
Disclosure
What happens after you report
- 01
Acknowledged
Within one business day, by a person rather than an autoresponder, with the name of whoever is picking it up.
- 02
Assessed
Within five business days we tell you whether we can reproduce it, how we rate the impact, and what we intend to do.
- 03
Resolved
Timeline depends on severity. You get progress rather than silence, and we tell you when the fix is live.
- 04
Closed
We confirm the outcome, credit you if you want to be credited, and agree any coordinated disclosure timing with you.
Access
Who can reach customer data
| Party | What they can reach | Control |
|---|---|---|
| Anyone with a data carrier | The public tier of a passport | The product group’s access policy |
| Verified third parties | Treatment, repair or regulatory tiers | A revocable credential from a trusted issuer |
| Customer systems | Everything in that tenant | Scoped keys, per environment and capability |
| CirculeID engineering | Production data, for an approved reason | Restricted, reason-required, logged in the customer-visible audit trail |
| Subprocessors | Only what their function requires | Named in the data processing terms; changes notified in advance |
Practices
What is in place
Encryption
In transit and at rest, with keys managed separately from the data.
Key custody
Signing keys in a hardware security module, or retained entirely by the customer.
Audit logging
Including our own operational access, in the trail customers can read.
Least privilege
Access granted per role and per reason, reviewed rather than accumulated.
Direct breach notification
Affected customers are told directly, early, and with what is still unknown.
Researcher-friendly
Good-faith reports are treated as a favour, not as a legal matter.
Answers
Frequently asked questions
How do I report a vulnerability?
Email ceo@fistasolutions.com with "Security disclosure" as the subject. Include enough detail to reproduce the issue. Please do not open a public issue, post it publicly, or test against other customers' data before we have had a chance to respond.
What do you commit to in response?
Acknowledgement within one business day, an initial assessment within five, and a named contact who stays with the report until it is closed. We will tell you what we found even when the answer is that the behaviour is intended, and we will credit you if you want to be credited.
Can CirculeID staff read customer passport data?
Production access is restricted, requires an approved reason, and is logged in the same audit trail customers can read. We do not claim zero-knowledge: the platform hosts the record and resolves it on request, so it necessarily processes the data. Any vendor claiming otherwise while serving a public passport is describing something the architecture cannot do.
What happens if there is a breach?
Affected customers are notified directly rather than through a status page alone, with what we know, what we do not yet know, and what we are doing. Notification obligations under the GDPR and any applicable sectoral rules are met on their statutory timelines. We would rather send an incomplete early notification than a tidy late one.
Do you run a bug bounty?
Not a formal programme with published bounty tiers. We do acknowledge and, where a report has real impact, reward researchers case by case. Announcing a bounty programme we could not administer consistently would be worse than being straightforward about how this currently works.
Next step
Send us your vendor assessment
We would rather complete your questionnaire directly than have you infer the answers from a page. Ask the hard ones.