Walvoil gives the utmost importance to cybersecurity and implements robust measures to safeguard its digital products and protect its supply chain.
The company is committed to analysing and addressing any reports of vulnerabilities promptly in order to prevent unauthorised exploitation and ensure the ongoing security of its products.
Should you discover a cybersecurity vulnerability in one of our products, please report it to our PSIRT (Product Security Incident Response Team) at the following email address: psirt@walvoil.com

To report cybersecurity vulnerabilities, please contact Walvoil’s PSIRT point of contact via the dedicated email address: psirt@walvoil.com
In particular, we would ask you to provide:
You should only demonstrate the existence of a vulnerability by limiting your actions to what is strictly necessary.
Unless expressly authorised, you are recommended to avoid altering configurations or disrupting the normal operation of the products.
Walvoil will examine and attempt to reproduce the reported vulnerability in order to assess its validity and scope. This process may involve key stakeholders from various departments, thereby ensuring a thorough analysis and a comprehensive approach to resolving the issue.
Where necessary, and provided that anonymity has not been requested, the person who reported the issue may be contacted to clarify any doubts and/or to obtain further information that may help to obtain a complete overview of the situation.
Once the vulnerability has been confirmed, a risk assessment will be carried out to determine its severity and evaluate its potential impacts and consequences.
Walvoil will proceed with defining, planning and deploying a resolution plan: activities may include the development of patches and updates or the optimisationof configurations.
The implementation of the aforementioned plan will follow an order of priority determined on the basis of the level of severity, impact and consequences assessed in the previous analysis.
Please note that, for phase-out products, Walvoil will only be able to provide recommendations, as it is not possible to offer corrective solutions.
During the process, the following requirements must be met:
Walvoil reserves the right to take legal action in the event of non-compliance.
Report an issue through the contact form
Walvoil would like to thank all the people, organizations and companies that, at their own discretion, reported and provided remediation to one or more vulnerabilities concerning our products.
Walvoil does not provide any monetary compensation (e.g. Bounty Bug) for vulnerability reports, in compliance with its Coordinated Vulnerability Disclosure (CVD) process.