Security Policy ← Back to Certification Portal

Security Policy & Vulnerability Disclosure

Overview

GVision Italia S.r.l. is committed to ensuring the security of our products and services through an ISO/IEC 27001:2022 certified vulnerability management process. We welcome security reports from the research community and provide a secure channel for coordinated disclosure.

security@gvision.it — Primary contact for security reports

Scope

In Scope

  • GVision Italia proprietary network devices (switches, PoE, IoT)
  • EU compliance modified firmware (GV-Certify process)
  • Video surveillance systems for critical infrastructure
  • GVision Italia web portals and cloud services
  • VMS management software and related APIs

Out of Scope

  • Unmodified GeoVision products not processed by GVision Italia
  • Third-party services not directly managed
  • Social engineering against employees or customers
  • DoS/DDoS attacks without prior authorization

Response Timeline

5 days
Report acknowledgment
10 days
Preliminary assessment and status update
30 days
Remediation plan and timeline
90 days
Coordinated disclosure (flexible for complex cases)

Safe Harbor Provisions

GVision Italia commits not to pursue legal action against researchers who:

  • Conduct good-faith research without causing damage
  • Avoid privacy violations of users and customers
  • Do not modify or delete data (limit to proof of concept)
  • Provide reasonable time for remediation before disclosure
  • Do not exploit vulnerabilities for personal gain

Activities conducted in accordance with this policy are considered authorized and will not violate the Computer Fraud and Abuse Act or similar regulations.

Report a Vulnerability

Prepare your vulnerability report using the form below. All fields will be included in your email client when you click submit. For critical vulnerabilities (CVSS ≥ 9.0), use PGP encryption.

Critical (9.0+) High (7.0-8.9) Medium (4.0-6.9) Low (0.1-3.9)
Note: Clicking “Prepare Security Report” will open your email client with all information pre-filled. Review the content before sending. For sensitive reports, use our PGP key.

Direct Contact for Critical Issues

security@gvision.it

PGP Key ID: A630747C6023C3A3
Fingerprint: AD2F 1BB0 22E8 A27C 983B  22F1 A630 747C 6023 C3A3
Algorithm: RSA 4096-bit · UID: GVision Italia

▼ Show full PGP public key block
-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGkKn8YBEACnH0I5tIs0YPT9oiHgTGFSflZzvvKcGqrf/wQ8M5DNK4fp5T5J
4u/hGEwNrbnjaUNATdcfiK6YS3RT1aSS0pIypblrjKTrXPgLUVLDSW+N4e314zAk
44ayOBFP7m5yWpp8mRTAls67A/4aqmXLvrSk3aI1C0cjkcnlNY3Bt5J4KqmGaTrU
kRLGzyU/itIsrFAMM89gMtJjGVavf4LSGNsDVpMbxdoGU8xnsDBzlAI9i3fozB0t
WCY308m8uU68m8ydG4PEO8gnJW01bN+6EoPi/pC0fBZdULgjSlcM8t3+Tf30f789
oqrCYtlO4q/Nc+fp6VNDvN6mltP6Mw7g3azii3wrZCkCwxWFaqENeVT+qQ8O8x0/
f/q95j8O5dhDTDfXq//n8Zt8byCtrU3Vqi9+h7/roFzBMUu0/aH21MYhezLZ4o/L
sHXO5haQwCEI02Lja6bteJWSYf52PTIXt7AqZRJRcSSK3fJFanUFUb6wxCFbIDbR
iH+dkTTtZu+MyvfqFqMClp3XklLjuR/zTyHQ3qFFr11rsnHCnYP4Nh8b7G/eQ+eO
V/foJ/otg+0B/jXg9XZqrSi0Y/i+U/euA9ZBL8faOSLGwGwIMk9EzRR5WNffZNw4
JWb+KLQISlyTa7XuBDnCYLuXPg3KB6s4NKgtiZeeQKSYfm2ik396rJXnZQARAQAB
tC1HVmlzaW9uIEl0YWxpYSA8Z3Zpc2lvbml0YWxpYUBwZWMuZ3Zpc2lvbi5pdD6J
AlcEEwEIAEEWIQStLxuwIuiifJg7IvGmMHR8YCPDowUCaQqfxgIbDwUJBaOagAUL
CQgHAgIiAgYVCgkICwIEFgIDAQIeBwIXgAAKCRCmMHR8YCPDozomD/9Tf17Hm0He
dEag/qJ+7TmsGgIq1CbhAdmOeIWm4UYmAvBlxIlPPdiyiL/298GHVY5zsin2QXed
/U3bIBfWaFIy/eBlB2AcZJD76d+FtIrx85eFs/t8jCGWg80rfruhFYNS+ZlSbrV4
V5lo/A31xTrqz4mY+O2TX/tPHwkdz0pu/jdKO5y6dcr4H31Hk6HgO1Fa9/cTVFWH
y4NR1JMp2O3pwG5ceUrOGScsr4+jMEV2SnY2hSQE+BO5sgG8CIgdMWDguDyqPA33
jBHrH1mLEL7fUOzAUVtQxzc7nrnVqd/rkAaO0+R8lccOCjC37Wa0c0Wi7e20Zz6a
D29gVgLjcH/L+eihLVE8CVZhDnwtV8B6ncDU/MISBPwl5RnQqKdAwrwCETVB/S28
JPaQ+2l28emUV6uq1+scE9jSLuOq4J0yYMWFWCvKejjnVGcdOGy2BXji8UvGcFus
zaz2xYQM1GhBJ215KlHZnclELCpWXhLw+40CR8wPKIjQe19dVo6Ah1LZ8uVFiVkI
QCz8ePzfXeQF5lhGHft9wj1NS7WA1a9iFdZfZVeojf3uDA5MeKPCm2qJF6ItBiU1
2FiFRma86MVLA3fsydadwIew0Kp34p7ppADnEfZSNzM0b5Gb36nmKs+AIZbYCaD3
ORLsA1T5rL+7ouDbhz/3+sF2pwkoniSG/Q==
=tiof
-----END PGP PUBLIC KEY BLOCK-----
        

Compliance & Standards

  • ISO/IEC 27001:2022 – Information Security Management System
  • ISO/IEC 29147 – Vulnerability Disclosure
  • GDPR Article 33 – Notification of Personal Data Breach
  • NIS2 Directive – Network and Information Security
  • CVE CNA Program – Coordinated Vulnerability Disclosure

Security Contact: security@gvision.it

CVE Program: GVision Italia — CVE Numbering Authority accreditata sotto ENISA Root (5 maggio 2026) · in coordinamento con GeoVision Inc. CNA

© 2026 GVision Italia S.r.l. – ISO/IEC 27001:2022 Certified

GVision Italia è GeoVision Italia: immettiamo sul mercato europeo i sistemi GeoVision e ne rispondiamo, come unica azienda italiana accreditata CVE Numbering Authority sotto ENISA Root.