Vulnerability Reporting

Embrava’s commitment to security

We prioritize ethical and responsible vulnerability disclosure. Our security team assesses each issue and oversees the process to ensure effective resolution in a timely manner in alignment with security best practices.

Our Process

How do I report a vulnerability?

If you have found a vulnerability in any Embrava products, please report it to:

Currently, Embrava does not have a bug bounty program. However, our security team diligently investigates all reported security issues. Kindly use this email exclusively for reporting security-related vulnerabilities.

What should I include?

Kindly include the following details:

  • A description of the vulnerability
  • The affected application and version
  • Steps to reproduce the vulnerability (Proof of Concept, if available)
  • Your preferred name for acknowledgment in the security advisory section

For other bug reports or support inquiries, please reach out to Embrava Support.

Response targets

Embrava tries to meet the following SLAs for vulnerabilities disclosed to us. We will keep you informed about our progress.

Type of response

SLA in business days

First response

2 days

Time to triage

3 days

Time to resolution

Depends on severity and complexity