
Claroty
Protect cyber-physical systems, reduce risks to your business, and increase operational efficiency with Claroty.
External Program
Submit bugs directly to this organization


Protect cyber-physical systems, reduce risks to your business, and increase operational efficiency with Claroty.
External Program
Submit bugs directly to this organization
As Claroty is very active in security research, the purpose of this Coordinated Disclosure policy is to (1) ensure that Claroty operates in accordance with an established and clear set of standards and practices, and (2) provides transparency with the ICS community regarding Claroty's practices.
Claroty is committed to privately reporting vulnerabilities to affected vendors in a coordinated, timely manner in order to ensure the security and safety of the OT ecosystem worldwide. We understand the community is a vital part of this process, and we want to explain our coordinated disclosure efforts. Claroty will adhere to the following reporting and disclosure process when its researchers discover vulnerabilities in products and services.
The following are the procedures that Claroty researchers will follow whenever a third party vulnerability is discovered:
Initial vendor outreach includes a statement regarding Claroty's policy that such vulnerability reports would be subject to an industry-standard 90-day public disclosure deadline:
This vulnerability is subject to a 90-day disclosure deadline; after 90 days, if a patch or mitigation has not been made available, Claroty will share information about this vulnerability with the public.
Should the vendor fail to answer within 15 days, Claroty will notify the relevant CERT, such as the Industrial Control System Computer Emergency Response Team (ICS-CERT) and provide them with a description of the vulnerability(ies).
Once patches are made available by the affected vendor to users, or if the 90-day disclosure deadline passes, Claroty will publish a public report informing users, and will provide additional details once a patch is released or advisory issued by the affected vendor(s).
Claroty is amenable to working closely with vendors on reasonable deadline extensions should the 90-day deadline not be feasible for patches or mitigations to be made available.
If a vendor is unresponsive and misses the 90-day deadline:
| Day | Action |
|---|---|
| Discovery | Attempt to securely communicate with vendor; Signatures developed for Claroty customers |
| 15 Days | Second secure email sent to vendor; CERT/ICS-CERT notification |
| 60 Days | Final reminder email sent to the vendor, informing them of the tentative release date of Claroty's public disclosure |
| 90 Days | Public disclosure: Publication of Claroty research paper/blog/social media outreach |