Skip to main content

    Responsible Disclosure Program

    At Securitas, we consider the security of our systems a top priority. But no matter how much effort we put into system security, there can still be vulnerabilities present. If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. We ask you to help us better protect our systems. Please report your findings through our webform below.

    Scope

    The following categories are in scope of Securitas Responsible Disclosure Program:

    • OWASP Top 10 Vulnerabilities
    • Server-Side Request Forgery (SSRF) — Must include evidence beyond basic interaction (e.g., external server response via Burp Collaborator or equivalent)
    • Remote Code Execution (RCE)
    • Account Takeover (ATO)
    • Authentication Bypass
    • Information Disclosure
    • Stored Cross-Site Scripting (Stored XSS)

    Please note that the above list shall not be read as being exhaustive and Securitas reserves the right to modify the above list at any time and for any reason.

    Out of Scope

    The following categories are explicitly out of scope of Securitas Responsible Disclosure Program and, thus, are not eligible for rewards:

    • Clickjacking
    • Open redirects
    • Reports of Publicly Known (Published) CVEs
    • Rate limiting tests involving fewer than 101 requests
    • Rate limiting on email subscription or signup forms
    • UI injection

    Responsible Disclosure Terms

    We kindly inform you that by submitting a report under our Responsible Disclosure Program, you agree to be bound by and are required to adhere to our Responsible Disclosure Terms. We strongly encourage you to read these terms carefully before submitting any report, as they contain important information regarding your rights (such as your possible right to a reward) and obligations. Click here to read the Responsible Disclosure Terms. Questions about the Responsible Disclosure Program can be sent to responsible.disclosure@securitas.com.

    Privacy

    When submitting a report to us, we will process the personal data that you submitted within your report and any additional personal data gathered during or after the resolution of the issue. Securitas Intelligent Services AB is the controller of your personal data, and the personal data is processed within our Legitimate Interest of Network and Information Security. We use the data to contact and communicate with you during and after the resolution process, possibly pay a reward, and, if you agree to this, name you as the discoverer of the issue in the public information. We will keep your personal data for as long as is necessary regarding report sensitivity, the sensitivity of personal data, and as required by law (if we pay a reward to you, we have a legal obligation to keep some information). You have rights as a data subject. To exercise these rights or ask a question, please contact privacy@securitas.com or our DPO at dpo@securitas.com. You also have the right to lodge a complaint with a supervisory authority.

    Submit your report

    Use this form to submit your responsible report to us. Please note that some of the fields are required.

    * = mandatory fields

    Confirm your e-mail address (Required)

    INSTRUCTIONS: Please visit the CVSS - Common Vulnerability Scoring System Version 3.1 Calculator website first.org/cvss/calculator/3.1 and fill in the information in the Base Score section. Enter the Base Score value and the Vector string value in the fields here below.

    INSTRUCTIONS: Please visit the CVSS - Common Vulnerability Scoring System Version 3.1 Calculator website first.org/cvss/calculator/3.1 and fill in the information in the Base Score section. Enter the Base Score value and the Vector string value in the fields here below.

    UPLOADING FILES: Maximum file size: 3 MG. Allowed file formats: jpg, png, pdf, xlsx.

    UPLOADING FILES: Maximum file size: 3 MG. Allowed file formats: jpg, png, pdf, xlsx.

    Accept terms and conditions (Required)

    Questions can be sent to responsible.disclosure@securitas.com.

    Questions can be sent to responsible.disclosure@securitas.com.

    ; ;
    Sorry, www.securitas.com does not support Internet Explorer. To enjoy our website, try using a newer browser like Chrome, Safari, Firefox, or Edge.