Overview
GVision Italia S.r.l. is committed to ensuring the security of our products and services through an ISO/IEC 27001:2022 certified vulnerability management process. We welcome security reports from the research community and provide a secure channel for coordinated disclosure.
security@gvision.it — Primary contact for security reports
Scope
In Scope
- GVision Italia proprietary network devices (switches, PoE, IoT)
- EU compliance modified firmware (GV-Certify process)
- Video surveillance systems for critical infrastructure
- GVision Italia web portals and cloud services
- VMS management software and related APIs
Out of Scope
- Unmodified GeoVision products not processed by GVision Italia
- Third-party services not directly managed
- Social engineering against employees or customers
- DoS/DDoS attacks without prior authorization
Response Timeline
Safe Harbor Provisions
GVision Italia commits not to pursue legal action against researchers who:
- Conduct good-faith research without causing damage
- Avoid privacy violations of users and customers
- Do not modify or delete data (limit to proof of concept)
- Provide reasonable time for remediation before disclosure
- Do not exploit vulnerabilities for personal gain
Activities conducted in accordance with this policy are considered authorized and will not violate the Computer Fraud and Abuse Act or similar regulations.
Report a Vulnerability
Prepare your vulnerability report using the form below. All fields will be included in your email client when you click submit. For critical vulnerabilities (CVSS ≥ 9.0), use PGP encryption.
Direct Contact for Critical Issues
security@gvision.it
PGP Key ID: A630747C6023C3A3
Fingerprint: AD2F 1BB0 22E8 A27C 983B 22F1 A630 747C 6023 C3A3
Algorithm: RSA 4096-bit · UID: GVision Italia
▼ Show full PGP public key block
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBGkKn8YBEACnH0I5tIs0YPT9oiHgTGFSflZzvvKcGqrf/wQ8M5DNK4fp5T5J
4u/hGEwNrbnjaUNATdcfiK6YS3RT1aSS0pIypblrjKTrXPgLUVLDSW+N4e314zAk
44ayOBFP7m5yWpp8mRTAls67A/4aqmXLvrSk3aI1C0cjkcnlNY3Bt5J4KqmGaTrU
kRLGzyU/itIsrFAMM89gMtJjGVavf4LSGNsDVpMbxdoGU8xnsDBzlAI9i3fozB0t
WCY308m8uU68m8ydG4PEO8gnJW01bN+6EoPi/pC0fBZdULgjSlcM8t3+Tf30f789
oqrCYtlO4q/Nc+fp6VNDvN6mltP6Mw7g3azii3wrZCkCwxWFaqENeVT+qQ8O8x0/
f/q95j8O5dhDTDfXq//n8Zt8byCtrU3Vqi9+h7/roFzBMUu0/aH21MYhezLZ4o/L
sHXO5haQwCEI02Lja6bteJWSYf52PTIXt7AqZRJRcSSK3fJFanUFUb6wxCFbIDbR
iH+dkTTtZu+MyvfqFqMClp3XklLjuR/zTyHQ3qFFr11rsnHCnYP4Nh8b7G/eQ+eO
V/foJ/otg+0B/jXg9XZqrSi0Y/i+U/euA9ZBL8faOSLGwGwIMk9EzRR5WNffZNw4
JWb+KLQISlyTa7XuBDnCYLuXPg3KB6s4NKgtiZeeQKSYfm2ik396rJXnZQARAQAB
tC1HVmlzaW9uIEl0YWxpYSA8Z3Zpc2lvbml0YWxpYUBwZWMuZ3Zpc2lvbi5pdD6J
AlcEEwEIAEEWIQStLxuwIuiifJg7IvGmMHR8YCPDowUCaQqfxgIbDwUJBaOagAUL
CQgHAgIiAgYVCgkICwIEFgIDAQIeBwIXgAAKCRCmMHR8YCPDozomD/9Tf17Hm0He
dEag/qJ+7TmsGgIq1CbhAdmOeIWm4UYmAvBlxIlPPdiyiL/298GHVY5zsin2QXed
/U3bIBfWaFIy/eBlB2AcZJD76d+FtIrx85eFs/t8jCGWg80rfruhFYNS+ZlSbrV4
V5lo/A31xTrqz4mY+O2TX/tPHwkdz0pu/jdKO5y6dcr4H31Hk6HgO1Fa9/cTVFWH
y4NR1JMp2O3pwG5ceUrOGScsr4+jMEV2SnY2hSQE+BO5sgG8CIgdMWDguDyqPA33
jBHrH1mLEL7fUOzAUVtQxzc7nrnVqd/rkAaO0+R8lccOCjC37Wa0c0Wi7e20Zz6a
D29gVgLjcH/L+eihLVE8CVZhDnwtV8B6ncDU/MISBPwl5RnQqKdAwrwCETVB/S28
JPaQ+2l28emUV6uq1+scE9jSLuOq4J0yYMWFWCvKejjnVGcdOGy2BXji8UvGcFus
zaz2xYQM1GhBJ215KlHZnclELCpWXhLw+40CR8wPKIjQe19dVo6Ah1LZ8uVFiVkI
QCz8ePzfXeQF5lhGHft9wj1NS7WA1a9iFdZfZVeojf3uDA5MeKPCm2qJF6ItBiU1
2FiFRma86MVLA3fsydadwIew0Kp34p7ppADnEfZSNzM0b5Gb36nmKs+AIZbYCaD3
ORLsA1T5rL+7ouDbhz/3+sF2pwkoniSG/Q==
=tiof
-----END PGP PUBLIC KEY BLOCK-----
Compliance & Standards
- ISO/IEC 27001:2022 – Information Security Management System
- ISO/IEC 29147 – Vulnerability Disclosure
- GDPR Article 33 – Notification of Personal Data Breach
- NIS2 Directive – Network and Information Security
- CVE CNA Program – Coordinated Vulnerability Disclosure