CyberSun

Security policy

Last updated: 14 September 2026

Report suspected vulnerabilities privately to security@cybersun.si. Include the affected SEMS version or build ID, reproduction steps, impact, and a safe way to contact you. Do not include customer data or credentials.

What to expect

We acknowledge reports within three working days, triage them promptly, and coordinate disclosure once a fix is available. Security updates are supplied without charge for five years from delivery. Supported releases are the current production release and any older release for which an upgrade is temporarily blocked by us.

Good-faith testing

Please do not open a public issue for an undisclosed vulnerability. Good-faith testing must avoid customer systems, denial of service, accessing data beyond the minimum needed to demonstrate the issue, persistence, and social engineering.

Varnostna politika

Domnevne varnostne ranljivosti zaupno prijavite na security@cybersun.si. Ne vključujte podatkov strank ali poverilnic. Prejem prijave potrdimo v treh delovnih dneh in razkritje uskladimo, ko je popravek na voljo.