Мы используем файлы cookie, которые представляют собой небольшие текстовые файлы, позволяющие улучшить ваши впечатления от нашего сайта и показать вам персонализированный контент. Вы можете разрешить все или управлять ими по отдельности.
Vulnerability Disclosure Policy
At Creative we are committed to building secure and resilient products and services. We welcome good faith reports of suspected vulnerabilities affecting Creative products, software, systems, or services, and we value those who help us identify and address security issues responsibly. Please review this policy carefully before conducting any research or submitting a report.
Scope
For purposes of this policy, "Creative products, software, systems, or services" includes:
Research conducted on a Creative Device that you have lawfully purchased and own is within scope. Testing of the companion applications and the associated cloud or backend services is within scope only to the extent conducted against accounts, data, or assets that you own or are expressly authorized to assess, or against public-facing assets that Creative has expressly identified as in scope. All research remains subject to the guidelines and prohibited activities set out below.
How to Submit a Report
When submitting a vulnerability report, please provide sufficient information to enable Creative to reproduce and assess the issue. Where available, your report should include:
We ask that researchers make reasonable efforts to avoid harm during security testing. Please do not take any action that could impair the confidentiality, integrity, availability, or safety of Creative products, software, systems, or services, or associated data. In particular, do not disable, bypass, or interfere with any product safety feature (including volume-limiting or hearing-protection controls) in a manner that could create a risk of physical harm to any user. Avoid accessing or retaining data beyond what is necessary to demonstrate the vulnerability, and stop testing immediately if you encounter sensitive data or risk service disruption.
Confidentiality and Coordinated Disclosure
Please maintain the confidentiality of your findings, along with any related information you learn or infer through your research, until we have completed our investigation and, where appropriate, implemented any necessary measures, and/or until we've coordinated disclosure with you. This helps protect our users and ensures the responsible handling of security issues. We'd appreciate you keeping this in mind even where we decide not to remediate, and even where the same or a related vulnerability might affect other Creative products, software, systems, or services that share a common component (for example, a chipset, codec, wireless stack, or licensed firmware).
Creative’s Response
Upon receipt of a report submitted under this policy, Creative will endeavor to:
Creative will use reasonable efforts to review reports and address confirmed vulnerabilities in a timely manner, but response and remediation timelines may vary based on issue complexity, product lifecycle, and operational constraints.
Guidelines for Permitted Research
This policy applies only to good faith security research conducted in a manner consistent with its terms. To remain within scope, you must:
Activities to Avoid
To keep your research in scope and protect our users, please avoid the following activities, which are not permitted under this policy:
Out of Scope Reports
Certain categories of findings are outside the scope of this policy or may not be prioritized for response. These include, without limitation:
Creative reserves the right to determine, in its discretion, whether a submission falls within scope and the priority assigned to it.
Legal Statement and Safe Harbor
If you conduct security research in good faith and in compliance with this policy, Creative will not initiate legal action against you solely on that basis, though we cannot bind third parties or law enforcement authorities.
This Safe Harbor applies only to the extent permitted by applicable law and only to claims Creative may bring on its own behalf. It does not provide immunity from third-party claims or liability under applicable law. If a third party initiates legal action in connection with activities Creative determines were conducted in compliance with this policy, we may, in our discretion, indicate that we regard such activities as authorized, but we are not obligated to provide legal representation, indemnification, or other support.
No Reward Program
While we are grateful for the time and effort researchers invest, this is not a paid program. Unless Creative expressly states otherwise in writing, submission of a report does not entitle the reporting party to any payment, bounty, compensation, public recognition, or other benefit.
Changes to This Policy
Creative may update, revise, suspend, or withdraw this policy at any time. The version in effect at the time the relevant activity occurred will govern Creative’s assessment of compliance.
Contact Information
To report a vulnerability or ask questions about this policy, please contact Creative through the security reporting channel at security@ctl.creative.com.