Privacy Notice for This Site
This notice covers productsecurity.xos.com — the vulnerability disclosure policy, the security advisories, and the reports sent to productsecurity@xos.com. It sits alongside the XOS Privacy Policy, which covers the rest of our web presence.
Controller. XOS, Inc., 15 Tech Valley Drive, East Greenbush, NY 12061, United States. For anything in this notice, write to productsecurity@xos.com.
What we collect
This site sets no cookies, runs no analytics and loads nothing from third parties. Every page is static HTML served from our own server, so simply reading it leaves no tracking of any kind.
Three things are processed:
Web server logs. Requests are logged with the page requested, the time, and the visiting address — with the final part of that address removed before the record is stored, so it cannot be traced back to an individual. Purpose: operating and troubleshooting the site.
Security logs. Administrative access to the server, and events indicating attempted misuse, are logged with the full source address. Purpose: protecting the server against unauthorized access.
Vulnerability reports. If you email us, we receive whatever you send — typically your name and email address, and any details you include about yourself or your organization. Purpose: assessing the report, fixing what needs fixing, and replying to you.
Why we are allowed to
For all three, the lawful basis under the UK and EU General Data Protection Regulation is legitimate interests (Article 6(1)(f)):
- Running a public disclosure channel. We cannot receive and act on vulnerability reports without processing the contact details of the person reporting.
- Security of the service. Recital 49 GDPR recognizes that processing to the extent strictly necessary to ensure network and information security is a legitimate interest. That is why security logs keep the full address where the site's own access log does not.
We do not sell this data, use it for marketing, or make automated decisions with it.
Reporting anonymously
You do not have to identify yourself. A report sent from an anonymous address, or with no name, is investigated on the same terms as any other. The only cost is that we cannot reply to you, credit you, or tell you when a fix ships.
If you would like to be credited in an advisory, tell us how you want to be named. We will not publish your name without that instruction.
Who else may see a report
A vulnerability report may need to be shared to get the issue fixed and disclosed responsibly:
- Within XOS, with the engineering and management staff handling the report.
- With our parent company, Veralto, where their product security function is involved.
- With a third-party supplier, where the vulnerability is in a component we did not write.
- With a CVE Numbering Authority or a national CSIRT, where the issue warrants a public identifier or a regulator must be notified.
We share the technical content, not your identity, unless you have asked to be credited or you agree to the introduction. Where a report must be forwarded to the operator of xos.com, we tell you.
Where the data goes
XOS is based in the United States and our systems are hosted there. If you write to us from outside the United States, your report is transferred there. For transfers from the UK or the EU we rely on Article 49(1)(b) GDPR, the transfer being necessary to act on a report you have chosen to send us.
How long we keep it
Server and security logs: twelve months, then deleted.
Vulnerability reports are kept for longer, and deliberately so. A report is the record of what was wrong with a product, what we changed, and when — evidence we may be required to hold and produce for as long as the affected product is supported. We keep a report for the support period of the product it concerns, plus twelve months. A report about something that turns out not to be ours, or to be out of scope, is kept for twelve months from closure.
When we close a report we keep your contact details only where there is a reason to — an open thread, a credit you asked for, or a promise to tell you when the fix ships. Otherwise we remove them and keep the technical content.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to our processing it — which, given the basis we rely on, is a right worth knowing about. Write to productsecurity@xos.com and we will respond within one month.
Where we cannot fully comply — for example where a report forms part of a record we are obliged to retain — we will tell you why.
If you are in the UK or the EU and you think we have handled your data badly, you may complain to your national data protection authority. We would rather you told us first.
Changes
Material changes to this notice will be recorded here with the date they took effect. This version: 2026-Aug-05.