Bronto Skylift Responsible Disclosure Procedure

At Bronto Skylift, we consider the security and safety of our systems, products, and connected fleet solutions a top priority. But no matter how much effort we put into cybersecurity, vulnerabilities can still occur.

If you discover a vulnerability, we want to know about it so we can take steps to address it as quickly as possible. We ask for your help to better protect our company, our customers and the safety of our equipment worldwide.

Please do the following:

Report your findings through our email security@brontoskylift.com to prevent critical information from falling into the wrong hands and to help us keep you updated on progress. For your findings to be eligible for the Bronto Skylift disclosure program, they must be reported through this service.

  • Do not take advantage of the vulnerability or issue you have discovered—for example, by downloading more data than necessary to demonstrate the vulnerability, or by accessing, deleting, or modifying telemetry and customer data.
  • Do not reveal the problem to others until it has been fully resolved.
  • Do not use attacks on physical security, social engineering, SaaS, spam, or third-party applications.
  • Do provide sufficient information to reproduce the problem so we can resolve it as quickly as possible. Usually, the IP address, URL, affected software version, or component details along with a description of the vulnerability will be sufficient, but complex vulnerabilities may require further explanation.

What we promise:

  • We will respond to your report within three (3) business days with our evaluation.
  • If you have followed the instructions above, we will not take any legal action against you in regard to the report.
  • We will handle your report with strict confidentiality and will not pass your personal details to third parties without your permission.
  • We will keep you informed of the progress towards resolving the problem.
  • In the public information concerning the resolved issue, we will give your name as the discoverer as a token of our gratitude and recognition (unless you desire otherwise).

Scope:

  • Digital Solutions & Domains: brontoskylift.com and associated cloud platforms including the Bronto One portal and IoT services
  • Products: All Bronto Skylift aerial platforms, control systems (e.g., Bronto+), Camera systems, Radio remote control devices, Gateways and connected equipment software.

We strive to resolve all vulnerabilities as quickly as possible, and we wish to play an active role in the ultimate publication of the issue after it has been resolved.

Bronto Skylift Vulnerability Disclosure Policy

At Bronto Skylift, the safety and security of our systems, products, and connected fleet solutions are our top priorities. But no matter how much effort we put into cybersecurity, vulnerabilities can still occur in any complex, modern ecosystem.

If you discover a security vulnerability, we encourage you to report it to us immediately. By working together, we can protect our global customers, our infrastructure, and the operational safety of our equipment worldwide.

How to Report a Vulnerability

To ensure critical data remains secure and to receive regular updates on our progress, please submit your findings through one of our designated channels:

  • Email: security@brontoskylift.com

Note: To be eligible for recognition under the Bronto Skylift disclosure program, vulnerabilities must be reported through these official channels.

Guidelines for Responsible Disclosure

To maintain a safe and coordinated disclosure process, we ask that you adhere to the following principles:

  • Avoid Exploitation: Do not exploit the vulnerability beyond what is strictly necessary to demonstrate its existence. Do not download excessive data, or access, modify, or delete any telemetry or customer data.
  • Maintain Confidentiality: Do not disclose or publish the vulnerability to third parties until it has been fully resolved by our team.
  • Prohibited Actions: Do not perform physical security attacks, social engineering, denial-of-service (DoS/DDoS) testing, spamming, or attacks against hosted SaaS and third-party applications.
  • Provide Actionable Details: Provide sufficient information to help us reproduce and validate the issue. This typically includes the relevant IP addresses, URLs, affected software versions, component details, and a clear description of the vulnerability.

Our Commitment to You

If you report a vulnerability in accordance with these guidelines, Bronto Skylift commits to the following:

  • Timely Response: We will acknowledge and provide an initial evaluation of your report within three (3) business days.
  • Legal Protection (Safe Harbor): We will not take legal action against you regarding your research or the submission of your report.
  • Strict Confidentiality: Your report and personal details will be handled with strict confidentiality. We will not share your identity with third parties without your explicit consent.
  • Progress Updates: We will keep you informed of our progress as we work toward a resolution.
  • Recognition: With your permission, we will publicly credit you by name as the discoverer of the vulnerability once the issue is resolved, as a token of our gratitude.

Policy Scope

Digital Solutions & Domains

  • brontoskylift.com and associated corporate web infrastructure
  • Bronto One portal and related cloud platforms
  • Integrated IoT networks and fleet management web services

Products & Hardware

  • All Bronto Skylift aerial work platforms and fire & rescue apparatus
  • Control systems (Bronto+)
  • Connected camera systems
  • Radio remote control devices
  • Telematics gateways and connected equipment software

We strive to remediate all verified vulnerabilities as swiftly as possible and look forward to collaborating with the security community on any eventual public disclosures.

Bienvenue à Bronto Skylift.
Veuillez choisir votre région/langue.

X