Skip to content

Vulnerability Disclosure Process

Vulnerability Disclosure Process

Scan2x takes the security of its products, services, and customers seriously. We welcome reports from security researchers and members of the public who believe they have identified a potential security vulnerability.

Please report suspected vulnerabilities to:
Email: support@@avantech.com.mt
Include as much of the following information as possible:
  • The affected product, service, website, or version
  • A description of the vulnerability
  • Steps required to reproduce the issue
  • The potential security impact
  • Any supporting screenshots, logs, or proof-of-concept code
  • Your preferred contact details
Please encrypt sensitive information where appropriate and do not include personal or customer data unless strictly necessary.
After receiving your report, we will aim to:
  • Acknowledge receipt within three business days
  • Review and validate the reported issue
  • Keep you informed of material progress
  • Work with you to understand and resolve the vulnerability
  • Coordinate public disclosure where appropriate
Resolution times will depend on the complexity, severity, and affected systems.
When conducting security research, please:
  • Avoid accessing, modifying, downloading, or deleting data belonging to others
  • Avoid disrupting our services or affecting system availability
  • Do not use social engineering, phishing, physical attacks, or denial-of-service testing
  • Do not introduce malware or use automated tools that generate excessive traffic
  • Stop testing and notify us immediately if you encounter personal, confidential, or customer information
  • Give us a reasonable opportunity to investigate and address the issue before making it public
This process applies to publicly accessible Scan2x systems, services, and products that are owned or operated by Scan2x.
Third-party services, customer-managed systems, and vulnerabilities in unsupported or outdated product versions may fall outside the scope of this process.
We will not pursue legal action against researchers who act in good faith, comply with this process, avoid harm, and make a reasonable effort to protect user privacy and data.
This statement does not authorise access to third-party systems or activity that would otherwise be unlawful.
We may acknowledge researchers who submit valid reports, subject to their consent. Avantech does not currently operate a bug bounty programme, and financial rewards are not guaranteed.
Thank you for helping us protect Scan2x and its customers.