Vulnerability Disclosure Policy
The Carrier Product Security Incident Response Team (PSIRT) employs a coordinated approach to vulnerability disclosure and publication. PSIRT determines the best path when issuing security advisories for our supported Carrier products and our affiliates. Whenever possible, published security advisories will be made publicly available on our Product Security website.
Reporters, Researchers, and Vendors are encouraged to engage Carrier and act responsibly and transparently, in alignment with our goal to respond effectively while protecting our customers. No external disclosure, discussions, or confirmation of issues will be released until after the PSIRT investigation is complete. Summary of steps taken:
- Acknowledgement of Report
- Investigation of Findings
- Validation of Unique Vulnerability
- Planned Remediation of Mitigations
- Security Advisory Communication Plan
- Disclosure of Vulnerability Publication