Core Commitment
PACOM prioritizes the security and privacy of our customers above all else.
We are dedicated to thoroughly investigating all reported security vulnerabilities promptly to safeguard our users.
Reporting Vulnerabilities
If you identify a security vulnerability in any PACOM product, please report it securely by:
– Email: security.unison@pacom.com
– PGP Key: https://pacomgroup.com/pgp-key/
When reporting, please provide:
– Details of the affected software/hardware versions.
– Relevant configuration parameters.
Rules of Engagement
– PACOM does not operate the systems using our products. All vulnerability reviews must be conducted on systems owned by the reviewer or explicitly authorized by the system owner for third-party review.
– Vulnerability reports that require configurations deviating from the “PACOM Unison Hardening guide” recommendations may not be eligible for investigation or patching.
Vulnerability Reporting Procedure
1. Acknowledgment: Upon receiving a valid vulnerability report, PACOM will acknowledge receipt and initiate an investigation.
2. Investigation & Resolution: We will investigate the reported issue thoroughly and work towards a resolution in a swift and transparent manner.
3. Communication: We will keep the reporter informed about the progress and resolution of the vulnerability.
4. Confidentiality: We kindly request that reporters maintain confidentiality regarding the vulnerability to ensure a smooth resolution process and provide adequate time for affected customers to apply patches.
5. Public Disclosure: Once a patch is released, details of the vulnerability (including credit to the reporter, unless anonymity is requested) will be publicly announced in the relevant product release notes.