The security of our systems is a priority; however, vulnerabilities may still be present. We believe in a shared responsibility model that valuesing the contributions of researchers, experts, and users. This disclosure policy aims to provide a clear framework for responsibly reporting flaws, to ensure their effective and secure remediation.
This disclosure policy applies only to vulnerabilities related to:
The digital infrastructures, service platforms, applications, and products developed by Orange Cyberdefense.
Orange Cyberdefense services accessible via the internet, as well as exposed internal systems.
Any vulnerability that may affect the confidentiality, integrity, or availability of Orange Cyberdefense data.
We consider vulnerabilities in this scope when they meet the following conditions:
They have not been previously reported or have not already been discovered by our own internal procedures (e.g., linked to a third-party editor)
Reports show that our systems do not fully conform to 'best practices' (e.g., security headers are missing)
It can be demonstrated that the exploitation of the reported vulnerability could have a significant impact on OCD, our users, or our customers, but theoretical impacts are excluded from the scheme's scope.
Domains are related to “Orange Cyberdefense Group” (*.orange.com and *.orange-business.com domains are excluded of this scope)
In the context of detecting and reporting vulnerabilities in Orange Cyberdefense environments, we are committed to collaborating with you to understand and resolve issues promptly.
We encourage you to report any potential security issues in our systems in accordance with the guidelines of this policy.
If you have identified a vulnerability, please send an email to: vulnerability@orangecyberdefense.com
In your report, please include the following information:
We recommend encrypting your communications using our public PGP key to ensure the confidentiality of the exchanges.
We are committed to :
We ask individuals reporting vulnerabilities to adhere to the following principles:
Orange Cyberdefense recognizes the importance of the work of security researchers and experts and sincerely thanks them for their efforts and participation in this policy.
As of now, we do not have a reward program and do not offer financial compensation for vulnerability reports.
However, once the vulnerability is resolved, we can coordinate a joint publication with the researcher if they wish. We reserve the right to publish a security notice to inform our clients and partners while anonymizing the researcher's name if they prefer.
This control procedure aligns with standard good practices in ethical security research and does not permit actions that violate the law or cause Orange Cyberdefense to be in breach of any of its legal obligations.
We are committed to not pursuing legal action against researchers who adhere to the principles of this policy and act in good faith to improve the security of our systems.
For any questions or to report a vulnerability, please contact us at vulnerability@orangecyberdefense.com
If your communication includes sensitive data, please encrypt your email using the Orange Cyberdefense CERT key
ID | 0xFCF7EB86AF855E78 |
Hash | C586 64A9 2EAB 767A 832A B1CD FCF7 EB86 AF85 5E78 |
Download the public key
All security bulletins are available at the following address:
This policy will be reviewed periodically and may be updated to ensure its effectiveness and alignment with current standards.