Our Security Commitment

Security is integrated into our product development process to help protect customers and their connected environments.

Responsible Handling

We carefully review, assess, and follow up on every submitted vulnerability report.

Timely Response

We aim to acknowledge every submitted vulnerability report within two business days.

Clear Communication

We provide timely progress updates and request further information when needed.

Ongoing Security Support

We address reported vulnerabilities throughout each product’s stated security support period.

Coordinated Vulnerability Disclosure Policy

Magewell appreciates security research conducted in good faith. This policy explains how to report potential vulnerabilities and the protections available for good-faith research.

Responsible Disclosure

Magewell welcomes reports of potential security vulnerabilities and encourages responsible disclosure through the reporting channels on this page.

Safe Harbor

Magewell will not initiate legal action against researchers who conduct good-faith security research in accordance with this policy. This protection applies only to claims under Magewell’s control and does not authorise unlawful activity or bind third parties.

Research Guidelines:

  • Test only systems, devices, and accounts you own or are authorised to test, and limit testing to what is necessary.
  • Do not access, modify, retain, or disclose another person’s data. Stop testing if such data is encountered.
  • Do not disrupt services, use social engineering, or exploit vulnerabilities for personal gain or harm.
  • Report vulnerabilities promptly and allow reasonable time for investigation and remediation before public disclosure.

Vulnerability Handling Process

Magewell follows a structured process to ensure that each vulnerability report is handled appropriately:

Report Received

We acknowledge and register the report for tracking and follow-up.

Validate & Assess

We reproduce the issue and assess its severity and impact.

Remediate & Test

We develop and validate an appropriate fix or mitigation.

Communicate & Close

We provide updates and communicate the resolution through official channels.

Product Lifecycle & Legacy Product Policy

Magewell provides security support according to the lifecycle and applicable security support period of each product.

Active Products

Products currently offered for sale receive security support throughout their stated support period.

Maintained Products

Discontinued products within their stated support period continue to receive security fixes.

End-of-Life Products

Products beyond their stated support period no longer receive routine security updates.

The support period starts from the date the product is placed on the Union market. Please refer to the packaging box for more details.

Report a Vulnerability

You can report a potential security vulnerability through our online submission form or by email.

Encrypted Email
Online Submission

Online Submission

Drag and drop Supporting Materials, or Browse
PDF, TXT, LOG, JPG, JPEG, PNG only. Up to 5 files, 10MB each, 30MB in total. Duplicate file names are not allowed; different extensions are OK
Submit

By clicking, you agree to our Vulnerability Reporting Policy and commit to not disclosing any vulnerability details to external parties before the vulnerability is fixed.

Vulnerability Submission Confirmation – [{ reportCode }]

Submit Another Report