LAW & SECURITY
Security and Responsible
Vulnerability Disclosure
Information Security at Excedo
Information security is a core part of Excedo Networks' operations. We take a systematic approach to protecting information, systems and services, and to preventing, identifying and managing security risks and incidents.
Excedo Networks' Information Security Management System (ISMS) is certified to ISO/IEC 27001:2022.
Despite our continuous and systematic approach to security, vulnerabilities may occur. If you discover or suspect a security vulnerability in a system or service owned or operated by Excedo Networks, we encourage you to report it to us responsibly.
This policy describes how security issues and vulnerabilities should be reported to Excedo and sets out the conditions that apply when conducting security testing of our systems and services.
Reporting a Security Vulnerability
Suspected or confirmed security vulnerabilities should be reported to Excedo's Security Operations Center (SOC):
Email: soc(a)excedo.se
To enable us to assess and handle your report as efficiently as possible, please include, where possible:
- the affected system, service, domain or URL;
- a clear description of the identified or suspected vulnerability;
- steps to reproduce the issue;
- a description of the potential impact or consequences; and
- relevant technical information or a limited proof of concept.
Please do not submit more personal data, authentication credentials, customer information or other sensitive information than is necessary to describe and verify the vulnerability.
Scope
This policy applies to internet-facing systems and services owned or operated by Excedo Networks.
Systems, applications and services owned or operated by third parties are not covered by this policy, even where they are used by or integrated with Excedo Networks' services, unless expressly stated otherwise.
If you are unsure whether a system is within the scope of this policy, please contact our SOC before conducting any testing.
Responsible Security Testing
We welcome security research conducted in good faith for the purpose of identifying and responsibly reporting security vulnerabilities.
Testing must be limited to what is reasonably necessary to verify the existence of a potential vulnerability. Once a vulnerability has been verified, further exploitation should be avoided.
Wherever possible, please use your own accounts and test data.
Testing must not create unnecessary risk or adversely affect Excedo Networks, our customers, users, suppliers or other third parties.
Prohibited Activities
The following activities are not permitted without prior written authorisation from Excedo Networks:
- denial-of-service (DoS/DDoS) attacks or other deliberate attempts to overload systems or services;
- testing that may adversely affect availability, stability or performance;
- aggressive or extensive automated scanning;
- brute-force attacks, credential stuffing or extensive automated login attempts;
- social engineering, phishing or other attempts to manipulate employees, customers, suppliers or other individuals;
- physical security testing;
- deleting, modifying, encrypting or destroying information;
- accessing or downloading more information than is necessary to verify a vulnerability;
- using authentication credentials belonging to another person;
- installing or distributing malware;
- establishing backdoors, persistent access or other mechanisms intended to maintain unauthorised access;
- exfiltrating data beyond what is strictly necessary to verify a vulnerability; and
- testing systems or services belonging to third parties that are not under Excedo Networks' control.
Automated tools may only be used with appropriate care and in a manner that does not cause abnormal load, disruption or other adverse effects on our services.
Personal Data and Sensitive Information
If you inadvertently gain access to personal data, authentication credentials, API keys, tokens, private keys, customer information or other confidential or sensitive information, you must immediately:
- cease any further access;
- not copy, download, modify, use or disclose the information;
- limit any documentation to what is necessary to demonstrate the vulnerability; and
- report the incident to soc(a)excedo.se.
Any information inadvertently stored locally must be handled securely and deleted as soon as it is no longer required for reporting purposes or when requested by Excedo Networks.
Proof of Concept
A limited proof of concept may be used where necessary to demonstrate and verify a vulnerability.
It must be limited to the minimum extent necessary. If it is possible to demonstrate that unauthorised access can be obtained, testing must cease without retrieving additional information, accessing other users' information or extending the level of access.
Handling Reported Vulnerabilities
Reported vulnerabilities are handled in accordance with Excedo's established information security, incident management and vulnerability management processes.
When we receive a security report, we aim to:
- acknowledge receipt within three business days;
- record the report and conduct an initial assessment;
- assess the vulnerability's potential impact and severity;
- request additional information from the reporter where necessary;
- take appropriate action based on risk and priority; and
- provide updates to the reporter where appropriate and reasonably practicable.
The time required to remediate a vulnerability depends on factors including its severity, associated risk, technical complexity, the systems affected, and the testing and changes required to implement a secure remediation.
Acknowledgement of receipt does not mean that Excedo has verified or accepted the reported vulnerability.
Responsible Disclosure
We ask that you do not publicly disclose technical details or other information relating to a reported vulnerability until Excedo Networks has had a reasonable opportunity to investigate, assess the risk and, where necessary, remediate the issue.
If public disclosure is appropriate, we encourage you to coordinate the timing and scope of the disclosure with us in order to minimise risk to Excedo Networks, our customers, users and other affected parties.
Good-Faith Security Research
Excedo Networks welcomes security research conducted responsibly and in good faith in accordance with this policy.
For security research to be considered to have been conducted in good faith, we expect you to:
- act for the purpose of identifying and reporting security vulnerabilities;
- comply with the limitations set out in this policy;
- make reasonable efforts to avoid harm, disruption and exposure of information;
- cease testing if it risks adversely affecting systems, information or users;
- report identified vulnerabilities to Excedo Networks without undue delay; and
- not use any access or information obtained for your own benefit, the benefit of others or for any other unauthorised purpose.
This policy does not constitute general authorisation to access Excedo's or our customers' systems, accounts or information.
If you are unsure whether a particular testing method is permitted, please contact soc(a)excedo.se before conducting the testing.
No Bug Bounty Programme
This policy does not constitute a bug bounty programme.
Reporting a security vulnerability does not constitute or imply any commitment by Excedo to provide financial compensation, a reward or any other form of remuneration.
Contact
Security-related enquiries and vulnerability reports should be sent to:
Excedo Security Operations Center, Digital Crimes Unit (SOC)
soc(a)excedo.se
Current contact information for reporting security vulnerabilities is also published in Excedo Networks' security.txt file.
Last updated: 1 October 2026
