CirculeID

Security

如何告诉我们哪里出了问题

若您发现了漏洞,下方列出了报告渠道与我们的响应承诺。若您正在评估我们,那里同样有一份关于我们访问权限所在的坦率说明。

已确认收到
1 个工作日
已评估
5 天内
致谢
如果您需要

Definition

我如何向 CirculeID 报告安全漏洞?

Email ceo@fistasolutions.com with "Security disclosure" as the subject and enough detail to reproduce the issue. We acknowledge within one business day and give an initial assessment within five, with a named contact who stays with the report until it is closed.

Please do not post it publicly first, and please do not test against other customers’ data. Beyond that we are not going to threaten researchers with legal language: a report made in good faith is a favour, and we will treat it as one.

披露

您报告之后会发生什么

四个步骤,并附上我们真正会遵守的时限,而不是拿来展示的时限。
  1. 01

    已确认收到

    一个工作日内由真人而非自动回复答复您,并附上接手此事者的姓名。

  2. 02

    已评估

    五个工作日内,我们会告知能否复现、如何评估影响,以及打算怎么做。

  3. 03

    已解析

    时间取决于严重程度。您得到的是进展而不是沉默,修复上线时我们会告知您。

  4. 04

    已结束

    我们会确认处理结果,若您愿意署名则予以致谢,并与您商定任何协同披露的时间安排。

访问

谁可以接触客户数据

按照供应商评估问卷的提问方式撰写。最后一行正是多数安全页面略去不谈的那一项。
按主体划分的客户数据访问权限,及其所受的控制措施
PartyWhat they can reach控制
Anyone with a data carrierThe public tier of a passportThe product group’s access policy
Verified third partiesTreatment, repair or regulatory tiersA revocable credential from a trusted issuer
Customer systemsEverything in that tenantScoped keys, per environment and capability
CirculeID engineeringProduction data, for an approved reasonRestricted, reason-required, logged in the customer-visible audit trail
SubprocessorsOnly what their function requiresNamed in the data processing terms; changes notified in advance

实践做法

已经具备什么

答疑

常见问题

我如何报告漏洞?

Email ceo@fistasolutions.com with "Security disclosure" as the subject. Include enough detail to reproduce the issue. Please do not open a public issue, post it publicly, or test against other customers' data before we have had a chance to respond.

作为回应,你们承诺什么?

一个工作日内确认收到,五个工作日内给出初步评估,并指定专人跟进直至报告结案。即便结论是该行为属于预期设计,我们也会告知调查结果;若您愿意具名,我们会予以致谢。

CirculeID 的员工能读取客户的护照数据吗?

生产环境访问受到限制,需经批准的事由,并记入客户可以查阅的同一份审计轨迹。我们不宣称零知识:平台托管这份记录并按请求解析,因此必然会处理数据。任何一边提供公开护照、一边作出相反宣称的供应商,描述的都是架构做不到的事。

如果发生数据泄露会怎样?

受影响的客户会收到直接通知,而不仅是一个状态页面,内容包括我们已知的、尚未确定的,以及正在采取的措施。GDPR 及适用行业规则下的通知义务,均在法定时限内履行。我们宁可发出一份不完整的早期通知,也不愿发出一份体面的迟到通知。

你们设有漏洞赏金计划吗?

这不是一个公布了赏金等级的正式项目。我们会确认每一份报告,并在报告确有实际影响时逐案给予研究者奖励。宣布一个我们无法稳定运营的赏金计划,还不如坦率说明目前的做法。

Next step

把贵方的供应商评估问卷发给我们

我们宁愿直接填写您的问卷,也不愿让您从一个页面里去揣摩答案。请尽管问最难的问题。

Index