Welcome to our Coordinated Vulnerability Disclosure channel.
If you conduct vulnerability research in good faith and in accordance with this policy, we consider your research to be authorized. We will work with you to understand and resolve the issue quickly, and Robovision will not initiate legal action against you regarding your research.
We aim to acknowledge receipt and begin initial triage of submitted reports within 24 hours. Validated reports involving active exploits are immediately escalated to our response team for containment and regulatory notification.
Give us a reasonable timeframe to remediate the vulnerability before publicly disclosing any details.
Do not access, modify, or delete customer data. Only use your own test accounts during research.
Do not attempt social engineering, spear-phishing, or physical attacks against our staff.
In-scope submissions:
- Remote Code Execution (RCE) on processing servers or agents.
- Authentication/authorization bypass on the platform dashboard or APIs.
- Unintended access to trained AI model files or customer datasets.
- Malicious file uploads (e.g., image parsing exploits, buffer overflows in image processing libraries).
- Injection flaws (SQLi, Command Injection) within API parameters or web interfaces