Last updated: August 2026
Security & Vulnerability Disclosure
Our Commitment to Security
At Renson, we are committed to developing and maintaining secure products and digital services. Security is an integral part of our design, development, deployment, and maintenance processes.
We recognize that security vulnerabilities may still be discovered despite extensive preventive measures. We therefore welcome responsible reports from security researchers, customers, partners, and other stakeholders and are committed to handling reported vulnerabilities through a Coordinated Vulnerability Disclosure (CVD) process.
Our goal is to identify, assess, remediate, and communicate vulnerabilities in a transparent and responsible manner while protecting our users and products.
Coordinated Vulnerability Disclosure
If you believe you have discovered a security vulnerability affecting a Renson product, service, or digital platform, we encourage you to report it to us.
We support Coordinated Vulnerability Disclosure and will work with reporters in good faith to investigate and address valid vulnerabilities.
We ask that you:
- Act responsibly and avoid actions that could negatively impact users, customers, systems, or data.
- Provide sufficient information to reproduce and validate the reported issue.
- Avoid publicly disclosing the vulnerability before remediation and coordinated disclosure activities have been completed.
- Avoid social engineering, denial-of-service testing, spam campaigns, or other disruptive activities.
- Respect privacy and confidentiality requirements during testing and reporting.
What We Consider a Valid Vulnerability
A reported issue may be considered a valid vulnerability when:
- It affects a Renson product, service, website, application, or supporting infrastructure.
- It demonstrates a security weakness that could impact confidentiality, integrity, availability, authenticity, or related security properties.
- Sufficient technical details are provided to allow investigation and validation.
The following may be considered out of scope:
- Reports lacking sufficient supporting information.
- Issues generated solely through automated scanning without validation.
- Previously known vulnerabilities that have already been remediated or publicly disclosed.
Reporting a Vulnerability
You can report security vulnerabilities through the following channels:
- Email: psirt@renson.be
- Vulnerability Reporting Form: https://renson.net/en-gb/contact-user-portal
Anonymous reporting is supported through our vulnerability reporting form.
Response and Handling Process
When a vulnerability report is received, we will:
- Acknowledge receipt within five working days whenever contact information is supplied.
- Provide initial assessment feedback within ten working days.
- Maintain communication throughout the investigation process.
- Treat reports confidentially to the fullest extent permitted by law.
- Protect personal information and not disclose reporter information without consent.
If additional analysis is required, we will provide status updates throughout the investigation process.
Vulnerability Disclosure
Confirmed vulnerabilities are handled according to our Coordinated Vulnerability Disclosure process.
Where appropriate, Renson will:
- Develop and deploy remediation measures or security updates.
- Coordinate disclosure activities with relevant stakeholders.
- Publish security advisories for affected products or services.
- Disclose validated vulnerabilities in a timely and responsible manner.
Our objective is to disclose validated vulnerabilities within 90 days whenever reasonably achievable and appropriate.
Security Advisories
Security advisories and vulnerability notifications relating to Renson products will be published through this website.
Continuous Improvement
Security is an ongoing process. We continuously review and improve our security practices, vulnerability management processes, and communication mechanisms.
We value collaboration with the security community and welcome responsible reports that help us strengthen the security and resilience of our products and services.
Feedback and Contact
For questions regarding product security or vulnerability reporting, please contact:
- Email: psirt@renson.be
- Postal address: Renson HQ, Maalbeekstraat 10, 8790 Waregem, Belgium