Ergosoft – Vulnerability Disclosure: Rules of Engagement
Version 1.0 · Effective June 2026 · Companion to the Ergosoft Vulnerability Disclosure Policy
These rules supplement the Ergosoft Vulnerability Disclosure Policy. By taking part in coordinated disclosure with Ergosoft, you agree to follow them.
Confidentiality and disclosure
- Treat all vulnerability information as confidential.
- Do not disclose any details to third parties without Ergosoft's explicit written consent.
- Keep your findings private until we have agreed a coordinated disclosure date with you.
Conduct during research
- Notify us as soon as possible after you discover a real or potential security issue.
- Use exploits only to the extent needed to confirm that a vulnerability exists.
- Do not use an exploit to access or exfiltrate data, establish persistent access, or pivot to other systems.
- Do not access, modify, or interact with data, licences, or accounts that are not your own.
- Use only your own or dedicated test accounts, licences, and devices.
- Make every effort to avoid privacy violations, data loss, and disruption to systems or users.
- If you encounter personal, customer, or confidential data, stop immediately, notify us, and do not copy or disclose it.
Prohibited activities
- Social engineering (phishing, vishing, impersonation) of Ergosoft staff, partners, or customers.
- Physical attacks or non-technical testing (e.g. office access, tailgating).
- Denial-of-service (DoS/DDoS) or load and stress testing against Ergosoft or customer systems.
- Installing malware, or making unauthorised or repeated changes to systems.
- Sharing your access, tools, or findings with third parties.
- Contacting Ergosoft staff directly about the status of a report, outside security@ergosoft.net.
- Any activity that violates applicable international, national, or local law.
What we focus on
To keep our response focused, the following generally do not qualify as vulnerabilities and may not receive a detailed response:
- Automated scanner, static-analysis, or dependency-scanner output without a demonstrated, exploitable impact.
- Missing binary-hardening or build-configuration best practices (e.g. ASLR/DEP, code-signing) with no concrete exploit.
- Findings that require physical access to the machine, or that assume the attacker already has administrator-level local privileges.
- Crashes or resource exhaustion affecting only the reporter's own session, with no code execution, privilege escalation, or impact on other users or data.
- Issues affecting only unsupported operating systems.
- Vulnerabilities in third-party or bundled components (please report these to the upstream vendor).
If you believe an excluded item has real security impact, tell us anyway at security@ergosoft.net and explain why.
Reports we may not respond to
- Hoaxes or fraudulent reports.
- Anonymous or unverifiable submissions.
- Generic reports without actionable evidence.
- Reports unrelated to Ergosoft's products, services, staff, or customers.
- Requests for specific fix or disclosure timelines.
- Communications containing abusive language.
Legal protection
We will not pursue legal action against researchers who act in good faith and follow the Vulnerability Disclosure Policy and these rules. Failure to follow these rules may, however, result in removal from coordinated disclosure with Ergosoft and forfeiture of any acknowledgement or credit.
