PRODUCT SECURITY

Report a security vulnerability

Send vulnerability information to the Product Security Incident Response Team (PSIRT), not to general sales or support channels.

01

Preferred reporting channel

Email PSIRT

security@mobile-id.vn

Subject: [VULNERABILITY] Product / version / short summary

For highly sensitive evidence, request an encrypted transfer channel in the first message. Do not send production secrets, private keys or personal data in plaintext.

02

Include these details

  • Affected product, module, version and environment.
  • Endpoint, component or file format.
  • Impact and attacker prerequisites.
  • Reproduction steps and minimal proof of concept.
  • Redacted logs/screenshots and correlation identifiers.
  • Whether exploitation is active or only theoretical.
  • Preferred contact and disclosure timeline.

03

What happens next

StageTarget process
AcknowledgmentPSIRT confirms receipt and tracking ID
TriageValidate scope, severity and duplication
CoordinationRequest evidence, define mitigation and disclosure plan
RemediationFix, test, release and publish advisory as appropriate
ClosureCredit/acknowledgment where consented and evidence retained

04

For security researchers and automated tools

This technical resource supports automated discovery and does not replace the reporting guidance above.

Machine-readable security contact

View security.txt — RFC 9116

Plain text · HTTPS · no authentication, cookies or JavaScript required.