CirculeID

Security

How to tell us something is wrong

If you have found a vulnerability, the reporting route and our response commitments are below. If you are evaluating us, so is an honest account of where our access exists.

Acknowledged
1 business day
Assessed
Within 5 days
Credit
If you want it

Definition

How do I report a security vulnerability to CirculeID?

Email ceo@fistasolutions.com with "Security disclosure" as the subject and enough detail to reproduce the issue. We acknowledge within one business day and give an initial assessment within five, with a named contact who stays with the report until it is closed.

Please do not post it publicly first, and please do not test against other customers’ data. Beyond that we are not going to threaten researchers with legal language: a report made in good faith is a favour, and we will treat it as one.

Disclosure

What happens after you report

Four steps, with the timings we hold ourselves to rather than aspirational ones.
  1. 01

    Acknowledged

    Within one business day, by a person rather than an autoresponder, with the name of whoever is picking it up.

  2. 02

    Assessed

    Within five business days we tell you whether we can reproduce it, how we rate the impact, and what we intend to do.

  3. 03

    Resolved

    Timeline depends on severity. You get progress rather than silence, and we tell you when the fix is live.

  4. 04

    Closed

    We confirm the outcome, credit you if you want to be credited, and agree any coordinated disclosure timing with you.

Access

Who can reach customer data

Written as a vendor assessment asks it. The last row is the one most security pages leave out.
Access to customer data by party and the control that governs it
PartyWhat they can reachControl
Anyone with a data carrierThe public tier of a passportThe product group’s access policy
Verified third partiesTreatment, repair or regulatory tiersA revocable credential from a trusted issuer
Customer systemsEverything in that tenantScoped keys, per environment and capability
CirculeID engineeringProduction data, for an approved reasonRestricted, reason-required, logged in the customer-visible audit trail
SubprocessorsOnly what their function requiresNamed in the data processing terms; changes notified in advance

Practices

What is in place

Answers

Frequently asked questions

How do I report a vulnerability?

Email ceo@fistasolutions.com with "Security disclosure" as the subject. Include enough detail to reproduce the issue. Please do not open a public issue, post it publicly, or test against other customers' data before we have had a chance to respond.

What do you commit to in response?

Acknowledgement within one business day, an initial assessment within five, and a named contact who stays with the report until it is closed. We will tell you what we found even when the answer is that the behaviour is intended, and we will credit you if you want to be credited.

Can CirculeID staff read customer passport data?

Production access is restricted, requires an approved reason, and is logged in the same audit trail customers can read. We do not claim zero-knowledge: the platform hosts the record and resolves it on request, so it necessarily processes the data. Any vendor claiming otherwise while serving a public passport is describing something the architecture cannot do.

What happens if there is a breach?

Affected customers are notified directly rather than through a status page alone, with what we know, what we do not yet know, and what we are doing. Notification obligations under the GDPR and any applicable sectoral rules are met on their statutory timelines. We would rather send an incomplete early notification than a tidy late one.

Do you run a bug bounty?

Not a formal programme with published bounty tiers. We do acknowledge and, where a report has real impact, reward researchers case by case. Announcing a bounty programme we could not administer consistently would be worse than being straightforward about how this currently works.

Next step

Send us your vendor assessment

We would rather complete your questionnaire directly than have you infer the answers from a page. Ask the hard ones.

Index