Coordinated Vulnerability Disclosure (CVD) Policy

1. Purpose and Scope

This policy establishes the approach of KONE Corporation and its affiliates ("KONE ") to receiving, handling, and disclosing vulnerabilities in KONE Products with Digital Elements (PDE) and their supporting services. PDE refers to any software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately. In KONE context, this covers on-site equipment (e.g., elevator controllers, gateways, IoT devices, embedded firmware), associated mobile applications, and remote data processing solutions required for product functionality (e.g., backend services, cloud applications). This definition follows the EU Cyber Resilience Act (CRA), Article 3(1). This policy is intended to apply globally across KONE Corporation and its affiliates, subject to applicable local laws and regulatory requirements. Where local legal requirements impose additional or conflicting obligations, those requirements take precedence. 

 

KONE welcomes vulnerability reports from external researchers, customers, partners, and other stakeholders regarding KONE PDE and associated services. 

 

KONE is committed to coordinated vulnerability disclosure and to providing safe harbor for good-faith security research, as described in this policy. 

 

This policy applies to: 

 

  • KONE products with digital capabilities that are released and used in customer or operational environments 
  • Associated software, firmware, mobile applications, APIs, and cloud-based services required for product functionality 

 

Out of scope: 

 

  • Corporate IT infrastructure, internal enterprise services, and corporate/marketing websites not associated with KONE products 
  • Development, staging, and test environments not part of released products 
  • Systems or components outside KONE PDE and their associated services 

 

KONE evaluates whether reported issues fall within the scope of this policy. Reports related to items outside this scope may be redirected or handled through other applicable processes.

2. Policy Intentions

This CVD policy is a public commitment by KONE to receive and handle vulnerability reports in good faith, offering assurances that KONE does not or seek to retaliate against reporters acting responsibly and in good faith, while committing to investigate reports, communicate transparently, and coordinate disclosure timelines in order to reduce risk and protect users.
 

KONE asks for coordination to protect users, not for silence. KONE does not require NDAs to submit a report, though KONE and the reporter may voluntarily agree on confidentiality arrangements to support coordinated remediation and disclosure; KONE does not seek to restrict lawful publication. sfjalskfdj

3. Stakeholder Roles

  • Reporter: Any individual or organization that notifies KONE of a potential vulnerability.
  • Coordinator: An intermediary who may facilitate communication between KONE and other vendors or reporters, especially for multi-party vulnerabilities.
  • Manufacturer (KONE): Responsible for remediating vulnerabilities and publishing advisories.
  • User: Receives advisories and remediation information to make informed risk decisions.

4. Reporting Mechanisms

KONE provides a technically current and usable vulnerability reporting mechanism:

Reporters may also request confidential handling of their report.

5. Vulnerability Report Contents

Reporters are encouraged to provide:

  • Product or service name and affected version(s)
  • Technical description and steps to reproduce
  • Proof-of-concept code or evidence
  • Impact and severity estimate
  • Disclosure plans (embargo/publication timeline)
  • Contact information (optional for anonymous reports)
  • Any other relevant details to support analysis and remediation

 

See Appendix A for more details. 

6. Monitoring

KONE monitors vulnerability information sources relevant to Products with Digital Elements (PDE), including:

  • External sources:
    • Public vulnerability databases
    • Published advisories and
    • Vulnerability reports received via KONE’s disclosure mechanisms.
  • Supplier ecosystem: Vulnerability disclosures and advisories from suppliers of KONE.
  • Internal sources:
    • Security testing
    • Product assessments, and 
    • lifecycle reviews.
  • Automated monitoring: Monitoring of third-party and open-source components used within PDE via automated mechanisms (e.g., SBOM-based correlation).

7. Acknowledgement and Response

  • KONE aims to acknowledge receipt of vulnerability reports within 7 calendar days and provide initial status information where possible.
  • If additional information is needed, KONE will contact the reporter using the agreed communication method.

8. Assessment and Investigation

  • Initial triage is performed to assess validity, severity, and scope.
  • Duplicate reports are identified and consolidated.
  • If a report is not considered a vulnerability or in scope of this policy, the reporter is informed.

9. Ongoing Communication

  • KONE maintains open, cooperative dialogue with reporters and stakeholders.
  • Status updates, significant new information, and changes to plans are communicated promptly.
  • Embargo periods and disclosure timelines are coordinated with reporters and other relevant stakeholders as needed. KONE seeks to agree disclosure timeframes that appropriately balance risk reduction, technical complexity, product safety, supply-chain dependencies, and coordinated disclosure needs.
  • KONE does not seek a publication veto.

10. Coordination

For multi‑vendor or systemic issues, KONE coordinates directly or via a trusted coordinator (e.g., a national CSIRT) at the reporter’s or our request. Reporters may choose to involve their CSIRT at any time.

11. Advisory Publication

KONE publishes vulnerability information in a timely and proportionate manner to help users understand affected products, available remediation, and any actions they may need to take.

 

For vulnerabilities requiring coordinated public disclosure, KONE may publish a vulnerability advisory containing, as applicable:

  • Advisory and vulnerability identifiers, such as a KONE advisory ID, CVE ID, or other relevant identifier)
  • Date and time of publication
  • Title and overview
  • Affected products and versions
  • Impact, severity, and remediation steps
  • References and contact information
  • Revision history and terms of use.

Vulnerabilities that are discovered internally and addressed through normal product or service development are typically disclosed through release notes or equivalent product/service communication channels, provided this gives users sufficient information about the fixed vulnerability and available remediation.

 

Where a vulnerability involves external coordination, a reporter, multi-party handling, significant customer impact, or other circumstances requiring formal disclosure, KONE may publish a dedicated vulnerability advisory instead of, or in addition to, release notes.

12. Recognition

KONE may credit reporters in advisories if desired by the reporter. KONE’s Bounty program is separate from this CVD policy; participating in or being eligible for that is not required to report a vulnerability.

KONE is committed to providing safe harbor for good‑faith security research. If you:

  • Report promptly, avoid privacy harm, do not extort, and limit testing to the minimum needed to demonstrate impact; and
  • Do not intentionally disrupt KONE services (e.g., no DDoS, ransomware, or destructive tooling) or access data beyond what is strictly necessary to evidence the issue; then, to the maximum extent permitted by law, KONE will not initiate or support legal action against you, will not refer your activities to law enforcement for investigation, and will not pursue claims under our Terms of Service or similar restrictions for good‑faith CVD activities. We do not require NDAs to submit a report and do not require identity verification; anonymous reports are accepted. Coordination is requested, not coerced.

14. Disclosure Timeline

KONE supports coordinated vulnerability disclosure and seeks to agree reasonable disclosure timelines with reporters and other affected stakeholders.

Target disclosure and remediation schedules are determined on a case-by-case basis, taking into account factors such as vulnerability severity, exploitation risk, customer impact, product safety considerations, technical complexity, supply-chain dependencies, and the need for coordinated disclosure across multiple parties.

 

KONE aims to maintain open communication throughout the vulnerability handling process and will provide status updates and mitigation information when appropriate.

 

KONE does not seek a publication veto.

 

For vulnerabilities affecting products provided or sold in China, KONE handles disclosure in accordance with applicable Chinese vulnerability management requirements. KONE will not publish or facilitate publication of unpublished vulnerability details before a fix or effective mitigation is available, unless the case has been assessed and handled in accordance with applicable Chinese regulatory requirements. Where Chinese regulatory requirements apply, they override the standard coordinated disclosure practices described in this policy.

15. Policy Review and Updates

This policy is reviewed annually and updated as needed to reflect changes in standards, regulations, and KONE practices.

 

To report a potential security vulnerability affecting a KONE product or solution, please email security@kone.com or follow the Cybersecurity instructions on: https://www.kone.com/global/en/contact-us.html.

Appendix A

  1. Product or Service Name, URL, or Affected Version Information
    Clearly specify the product/service, including version numbers, build numbers, or URLs. 
  2. Operating System of Involved Components
    Indicate the OS (e.g., Windows 11, Ubuntu 22.04) if relevant to the vulnerability. 
  3. Version Information
    Provide detailed versioning for all affected components (software, firmware, hardware). 
  4. Technical Description
    Describe what actions were being performed and the observed result, in as much detail as possible. 
  5. Sample Code or Proof-of-Concept (PoC)
    Include any code, scripts, or commands used to test or demonstrate the vulnerability. 
  6. Reporter’s Contact Information
    Name, email, phone, or preferred method of contact (optional for anonymous reports). 
  7. Other Parties Involved
    List any other organizations, vendors, or coordinators who have been notified or are involved. 
  8. Disclosure Plans
    State any intentions regarding public disclosure, including embargo periods or desired publication timelines. 
  9. Threat/Risk Assessment
    Provide an assessment of the risk or threat, including a risk level (e.g., high, medium, low) and reasoning.
  10. Software/Device Configuration
    Describe the configuration of the system or device at the time of discovery (e.g., settings, enabled features).
  11. Connected Components and Devices
    Note any relevant information about other components or devices involved, especially if the vulnerability arises from their interaction.
  12. Time and Date of Discovery
    When was the vulnerability first observed or discovered?
  13. Browser Information

If applicable, specify browser type and version (e.g., Chrome 120.0, Firefox 119.0).

 

________________________________________
 

Why These Details Matter

  • Reproducibility: The more context and specifics provided, the easier it is for KONE’s security team to reproduce and verify the issue.
  • Prioritization: Risk and impact details help KONE triage and address the most critical vulnerabilities first.
  • Coordination: Information about other parties and disclosure plans supports effective, responsible, and coordinated disclosure.