Mobile-ID / Certificates & scope
RAR/C06 · eID / SSO / ShareInfoISO/IEC 24745:2022
Phase 7 publication editionPOL-VULNERABILITY-DISCLOSURE

Vulnerability reporting

Report concerns and coordinate assessment without granting testing permission.

Full public textOrganization/contract scoped

This is the full text published in the Phase 7 package. Effective dates, responsible contacts and contract-specific parameters are maintained in the corresponding release and deployment records.

01

Scope and testing authority

This policy describes reporting, not permission to attack, scan systems, collect data or bypass access controls. Active testing requires a written scope, environment, period, contacts and stop conditions agreed in advance.

02

Existing contact route

Reporters can contact info@mobile-id.vn to request a secure submission route. General email should identify the product, version, concern category and contact method. Do not send secrets, tokens, biometrics, other people's data or sensitive details before a suitable receiving channel is confirmed.

03

Minimum reporting information

A report should include affected version, reproduction conditions within an authorized environment, expected/actual behavior, observed impact and timeline. Prefer synthetic data. Redact sensitive evidence and provide only what is necessary to establish the issue, without further exploitation.

04

Triage and ownership

Intake records a case reference, checks scope and contactability, and assigns product/security ownership. Device, SDK or engine concerns are coordinated with the supplier within the agreed relationship. Evidence of an active incident enters incident response rather than remaining only in a bug queue.

05

Assessment and remediation

The assigned team validates in a controlled environment and records impact, affected versions and mitigations. Fixes are versioned, regression-tested and accompanied by deployment/rollback instructions. Suppliers and customers receive only information needed for authorized remediation.

06

Coordinated publication

Publication is risk-assessed and coordinated, identifying affected versions, remedies and customer guidance. This draft creates no bounty program, liability safe harbor or fixed disclosure schedule. Reporter attribution requires appropriate permission and consent.

07

Closure and records

Close after recording the conclusion, fix or rationale, stakeholder communication and trackable deployment. Sensitive reports have access controls and retention schedules. Aggregate reporting excludes personal data, secret configurations and details not cleared for publication.

Responsibility & deployment annex

Detailed responsibilities are determined by activity and deployment records; this public document does not replace customer-specific contractual annexes.

  • The relying organization defines business purposes, populations and operational authority within the deployment.
  • Mobile-ID supplies and operates components within the agreed scope, including integration, control configuration and related evidence.
  • Device suppliers support models, firmware, SDKs and maintenance within authorization; data access is never implicit.
  • Legal, security and service ownership assignments are maintained in each organization’s operating records.

Execution and evidence cycle

  1. Record purpose, organization, data/device scope and the business reference.
  2. Verify authority, applicable conditions, configuration and relevant obligations.
  3. Execute with data minimization, authorization and necessary evidence.
  4. Close with confirmations from relevant systems, response handling and remaining exceptions.

Legal and reference sources

Detailed obligations, periods and exceptions apply according to law, contract and the actual service configuration.

Contact about applicability

Send contact details and a general question only; sensitive records require a confirmed channel.

info@mobile-id.vn

Search Trusted Palm ID

Selected interface