WISE Group — Version 1.1, 8 September 2026
Reporting a vulnerability
If you believe you have found a security vulnerability in a WISE Group product, please contact us at psirt@wisegroupsystems.com.
Please include as much of the following as you can:
- The product and version affected
- A description of the issue and its impact
- Steps to reproduce it
- Whether you intend to publish, and when
You can write in English or Norwegian. Our contact addresses are also published at wisegroupsystems.com/.well-known/security.txt.
If you have not heard from us within 10 working days, please resend your report to psirt@wisegroupsystems.com.
Scope
This policy covers the software WISE Group develops in-house (DADAS, Orbalux, RUPDB, AIM Embedded Software and PACE) and WISE Group hardware in which that software runs.
Not covered:
- Testing against live systems. Our products run on installations operated by our customers, and Orbalux is a live service. Do not test, scan or attempt to access any of them without our prior written approval. Contact us first and we will arrange it where appropriate.
- Third-party and OEM equipment. Sensors, cameras, networking and computing hardware made by others, and their operating systems, are the responsibility of their manufacturers. Report those to the manufacturer, and tell us as well so we can assess any effect on our products.
- Our corporate IT and websites, unless the finding concerns product security.
- Findings with no demonstrated security impact, including automated scanner output without supporting analysis.
What we will do
- Acknowledge your report as quickly as we can, normally within 5 working days.
- Assess it and tell you what we have found.
- Keep you updated while we work on it.
- Let you know when a fix is available, and before we publish anything.
- Credit you if you would like us to, or keep your report anonymous if you prefer.
We do not run a paid bug bounty programme.
What we ask
- Act in good faith. Do not access, change or delete anyone’s data, and do not disrupt any service.
- Stop testing as soon as you have demonstrated the issue.
- No social engineering, physical intrusion or denial-of-service testing.
- Give us 90 days from your report before publishing. If we need longer we will tell you why and agree a new date with you.
If you follow this policy, we will not take legal action against you in relation to your research.
Advisories
We publish a security advisory once a fix or mitigation is available, and we notify affected customers directly. Advisories state the affected products and versions, the impact and severity, and what you need to do. See Security Advisories.
WISE Group advisories never carry attachments and never link to software downloads. Updates are supplied only through your established WISE Group support channel. Treat any message that claims otherwise as fraudulent and report it to us.
Security updates and support
[OPTIONAL, PENDING SIGN-OFF: We provide security updates for a minimum of five years from delivery. The support period for a specific product is stated in its documentation and in the contract for that delivery, and may be extended under a maintenance agreement.]Regulatory reporting
Where a vulnerability in one of our products is being actively exploited, we are required under the EU Cyber Resilience Act to notify the relevant authorities and inform affected users. This is separate from public disclosure and does not change the timeline we agree with you.