Vulnerability Disclosure Policy
OBJECTIVE
Husky is committed to maintaining the security, availability, and integrity of its products, services, systems, and information. This policy establishes a process for external parties to responsibly report potential security vulnerabilities affecting Husky products, services, or technology assets. Our Product Security Incident Response Team (PSIRT) manages the review, assessment, investigation, and remediation of reported security vulnerabilities affecting Husky products and related technology solutions.
The PSIRT works collaboratively with internal stakeholders to evaluate reported concerns, coordinate appropriate response activities, and help reduce risk to Husky and its customers. This includes vulnerabilities that may affect software, hardware, connected services, websites, cloud environments, and other Husky-operated technologies.
Individuals who become aware of a potential security vulnerability are encouraged to report the matter to Husky for review. Husky values responsible reporting and is committed to evaluating submissions in accordance with applicable business, operational, and security requirements.
Husky supports and encourages responsible, good-faith identification and reporting of security vulnerabilities in accordance with this policy.
Where appropriate and consistent with legal, operational, and security considerations, Husky may coordinate disclosure of validated vulnerabilities following remediation.
Nothing in this Policy limits any lawful reporting rights or obligations that may apply to individuals, nor does it amend, supersede, or replace the terms of any agreement individuals may have with Husky.
SCOPE
Testing under this policy is authorized only against:
- Husky-operated internet-facing websites and services;
- Husky product software, firmware, or hardware that you own outright, or that you test with the documented written authorization of both the owner and the operator of that equipment;
- Husky software distributed for general download.
Testing is not authorized against any Husky machine, controller, HMI, robot, auxiliary system, or connected service deployed in a production or operational environment, whether operated by Husky, a Husky customer, or any third party. Husky equipment includes moving mechanical assemblies, high-pressure hydraulic systems, and heated components. Interaction with deployed equipment can cause physical injury, property damage, and product loss, and is prohibited under this policy regardless of intent. Such activities may also violate applicable laws, contractual obligations, customer requirements, terms of use, or other Husky policies and agreements.
If you believe you have identified a vulnerability affecting deployed equipment, report it under this policy. Do not attempt to validate it on live equipment.
REPORTING A SECURITY ISSUE
Husky takes the security of its products, services, systems, and information seriously. Individuals who believe they have identified a security vulnerability within the scope of this policy are encouraged to report the issue to Husky for review.
Reports should include sufficient detail to assist in evaluating the concern, including the affected product or service, a description of the issue, supporting information, reproduction steps where applicable, and any known potential impact.
After identifying a potential issue, individuals should act in good faith and limit testing to the minimum activity necessary to demonstrate the existence of the vulnerability. If sensitive, confidential, proprietary, or personal information is encountered, testing should cease immediately and the matter should be reported to Husky.
Reports may be submitted anonymously; however, providing contact information may assist Husky if additional information is required. Husky reviews submitted reports and may contact reporters when appropriate to support investigation and remediation efforts.
Subject to applicable law, Husky does not intend to pursue legal action against individuals who, in good faith, comply with this policy, limit their activities to those reasonably necessary to identify and demonstrate a potential vulnerability, promptly report their findings, and avoid actions that adversely affect the confidentiality, integrity, or availability of Husky systems, services, information, customers, or users.
Husky considers vulnerability testing conducted in good faith and in accordance with this policy to be authorized access for purposes of applicable computer crime and anti-circumvention laws, including the U.S. Computer Fraud and Abuse Act, the U.S. Digital Millennium Copyright Act, and sections 342.1 and 430(1.1) of the Criminal Code (Canada). If a third party initiates legal action against you in connection with such activity, Husky will make this authorization known. This authorization does not extend to systems, data, accounts, or equipment owned or operated by Husky customers, suppliers, or other third parties, and does not waive the rights of those parties. It does not authorize conduct that violates applicable law. If you are unsure whether specific conduct is authorized, contact Husky at coritsec@husky.ca before proceeding.
Where a reporter provides personal information, Husky will process such information in accordance with its Privacy Policy available here, which is incorporated into this policy by reference.
Husky Injection Molding Systems Ltd. acts as the controller of personal information submitted under this policy. Personal information is processed for the legitimate interests of receiving, investigating, and responding to vulnerability reports. Information will be retained only for as long as necessary to fulfill these purposes and comply with applicable legal requirements. Personal information may be transferred to and processed in the EU, USA, Canada and other jurisdictions identified in the Privacy Policy.
Husky's PSIRT serves as the central intake point for security reports. Reports relating to corporate information systems, websites, cloud environments, or internal technology assets may be routed to the appropriate internal cybersecurity or information technology teams for investigation and remediation. Product-related vulnerabilities will continue to be managed through the PSIRT process.
Please include the following information whenever possible:
- Description of the issue
- Affected product, system, application, or service
- Location where the issue was observed
- Steps required to reproduce the issue
- Relevant screenshots, logs, or supporting information
- Potential impact, if known
- Contact information for follow-up (optional)
GUIDELINES FOR REPORTING INDIVIDUALS
Individuals are asked to:
- Act in good faith to avoid privacy violations, service disruption, or destruction of data
- Limit testing to the minimum activity necessary to validate a vulnerability
- Do not access, retain, copy, transmit, or disclose customer, personal, confidential, proprietary, or other sensitive data except to the minimum extent strictly necessary to verify a vulnerability. Any sensitive data included in vulnerability reports must be redacted or otherwise sanitized to the greatest extent practicable.
- Individuals agree not to publicly disclose a reported vulnerability for ninety (90) days following Husky's acknowledgment of the report, unless otherwise agreed in writing by Husky and the reporter, required by applicable law, regulation, court order, or governmental authority.
- Where remediation requires a coordinated field service campaign or other operational measures affecting deployed production equipment, Husky may request a longer disclosure period, which it will seek to coordinate with the reporter in good faith
- Immediately report any inadvertent exposure to sensitive information
VULNERABILITY HANDLING AND DISCLOSURE
Husky will endeavor to acknowledge receipt of vulnerability reports within a reasonable timeframe, as determined based on the circumstances of the report, available resources, and applicable operational and security considerations, and will work with reporters to assess, validate, and remediate reported vulnerabilities.
Where applicable, Husky may assign Common Vulnerabilities and Exposures (CVE) identifiers through an authorized CVE Numbering Authority (CNA) and may coordinate public disclosure through relevant cybersecurity coordination bodies, including government agencies, sector-specific response organizations, and national Computer Security Incident Response Teams (CSIRTs).
OUT OF SCOPE ACTIVITIES
The following activities are not authorized under this policy:
- Social engineering of employees, contractors, customers, suppliers, or partners
- Physical security testing
- Denial-of-service (DoS) or distributed denial-of-service (DDoS) testing
- Spam, phishing, or unsolicited messaging campaigns
- Testing that in its intent or effect intentionally disrupts services or impacts users
- Extortion, threats, or requests for compensation in exchange for vulnerability information
BUG BOUNTY
Husky does not currently operate a public bug bounty program. No monetary compensation is offered or implied for vulnerability submissions, and submission of a report does not create any expectation of payment, reward, employment, consulting engagement, or other compensation. At its discretion and with the reporter's consent, Husky may publicly acknowledge individuals who responsibly report validated vulnerabilities.