Food Experts is committed to ensuring the security of its customers by protecting their information from unwarranted disclosure. This policy is intended to give security researchers clear guidelines for carrying out vulnerability discovery activities and to convey our preferences on how to report discovered vulnerabilities. This policy describes which systems and types of research it covers, how to submit vulnerability reports and how long security researchers must wait before publicly disclosing vulnerabilities. We want security researchers to feel comfortable reporting vulnerabilities so that they can be fixed. This policy has been developed to reflect our values and uphold our sense of responsibility towards security researchers who share their expertise with us in good faith.

Authorisation

If you make a good-faith effort to comply with this policy during your security research, we will consider your research authorised, work with you to understand and resolve the issue quickly and not recommend or pursue legal action related to your research. However, we do not offer monetary rewards for vulnerability disclosure.

Guidelines

Under this policy, “research” means those activities in which you:

  • Notify us as soon as possible after discovering a real or potential security issue
  • Make every effort to avoid privacy violations, degradation of the user experience, disruption to production systems and destruction or manipulation of data.
  • Only use exploits to the extent necessary to confirm the presence of a vulnerability. Do not use an exploit to compromise or exfiltrate data or to establish command-line access and/or persistence, and do not use the exploit to “pivot” to other systems.
  • Give us a reasonable amount of time to resolve the issue before making it public.
  • Do not intentionally compromise the privacy or safety of Food Experts personnel, customers or third parties.
  • Do not intentionally compromise the intellectual property or other commercial or financial interests of Food Experts personnel or entities, customers or third parties.

Once you have established that a vulnerability exists or have encountered any sensitive data (including personally identifiable information (PII), financial information, private information or trade secrets of any party), you must stop testing, notify us immediately and not disclose this data to anyone else.

Scope

All systems and services associated with the domains listed are in scope, including subdomains and any website with a link to this policy.

Vulnerabilities found in systems that do not belong to Food Experts are out of scope and must be reported directly to the vendor in accordance with its own Vulnerability Disclosure Programme (VDP) policy (if any).

Although we develop and maintain other internet-accessible systems or services, we ask that active research and testing be carried out only on the systems and services covered by the scope of this document. If there is a system out of scope that you think merits testing, please contact us to discuss it first.

ProductDomain
Food Expertsfood-experts.com
Food SecuritasFoodsecuritas.com

Rules of engagement
Security researchers must not:

  • Test any system other than the systems included in the “Scope” section (above)
  • Disclose vulnerability information, except as defined in the “Reporting a vulnerability” and “Disclosure” sections (below).
  • Carry out physical testing of facilities or resources.
  • Engage in social engineering.
  • Send unsolicited email to Food Experts personnel or customers, including “phishing” messages.
  • Execute or attempt to execute “denial of service” or “resource exhaustion” attacks.
  • Introduce malicious software.
  • Carry out testing that could degrade the operation of Food Experts systems or intentionally impair, disrupt or disable Food Experts systems.
  • Carry out testing on third-party applications, websites or services that integrate or link with Food Experts systems.
  • Delete, alter, share, retain or destroy Food Experts data, or render Food Experts data inaccessible.
  • Use an exploit to exfiltrate data, establish command-line access, establish a persistent presence on Food Experts systems or “pivot” to other Food Experts systems.

Security researchers must:

  • Stop testing and notify us immediately if you discover any vulnerability.
  • Stop testing and notify us immediately if you discover any exposure of non-public data.
  • Delete any stored Food Experts non-public data after reporting a vulnerability.

Security researchers may:

  • View or store Food Experts non-public data only to the extent necessary to document the presence of a potential vulnerability.

Reporting a vulnerability

We accept vulnerability reports at customer.support@food-experts.com

Information submitted under this policy will be used for defensive purposes only, that is, to mitigate or remediate vulnerabilities. If your findings include newly discovered vulnerabilities that affect all users of a product or service and not solely Food Experts, we may share your report with the Cybersecurity and Infrastructure Security Agency (CISA), where it will be handled under its coordinated vulnerability disclosure process. We will not share your name or contact information without your express permission.

By submitting a vulnerability report, you indicate that you have read, understood and accepted the guidelines described in this policy for conducting security research and disclosing vulnerabilities or indicators of vulnerabilities relating to Food Experts information systems, and you consent to the content of the communication and the follow-up communications being stored on a Food Experts system.

To help us triage and prioritise communications, we recommend that your reports:

  • Comply with all legal terms and conditions.
  • Describe the vulnerability, where it was discovered and the potential impact of its exploitation.
  • Offer a detailed description of the steps needed to reproduce the vulnerability (proof-of-concept scripts or screenshots are helpful).

Disclosure

Food Experts is committed to correcting vulnerabilities in a timely manner. However, we recognise that public disclosure of a vulnerability without immediate corrective action increases the risk. We therefore ask that you refrain from sharing information about discovered vulnerabilities for 90 calendar days after you receive our acknowledgement of receipt of your report. If you believe that others should be informed of the vulnerability before we implement corrective measures, we ask that you coordinate with us in advance.

We may share vulnerability reports with the Cybersecurity and Infrastructure Security Agency (CISA), as well as with the affected vendors. We will not share the names or contact details of security researchers unless we are given explicit permission.

Verification and remediation

The Food Experts General Manager (or their delegate) will be responsible for keeping an audit trail of public reports, verifications and remediations. Verification and remediation will be assigned to the relevant team members according to the source of the vulnerability.

Verification and remediation procedures

  • On receipt of an email, the Food Experts General Manager (or their delegate) is responsible for calling a team meeting and deciding who should respond and the level of response.
    • The level of response will include verifying the threat and communicating with the source.
  • The Food Experts General Manager (or their delegate) will also be responsible for determining the severity of the threat; for example, the vulnerability may constitute a security incident and require the involvement of other staff within the wider Volaris organisation.

Review and revision

At a minimum, this policy will be reviewed annually, or more frequently if deemed appropriate. The review of the policy will be carried out by Food Experts.

Last updated: September 2026