The Haverford Product Security Incident Response Team (PSIRT) is responsible for receiving, investigating, and coordinating the disclosure of security vulnerabilities in Haverford products and services, including the brands PTZOptics and HuddleCamHD. We work with security researchers, customers, and partners to ensure vulnerabilities are addressed in a timely and responsible manner.

Reporting a Vulnerability

If you have discovered a potential security vulnerability in a Haverford product or service, we encourage you to report it to us promptly. We are committed to working with you to understand, validate, and remediate the issue.

To submit a vulnerability report, use our secure reporting form or send an email to psirt@havsys.com. We request that you practice responsible disclosure and allow us a reasonable timeframe to investigate and address the vulnerability before any public disclosure.

Submit a Vulnerability Report

Secure Communication

For sensitive vulnerability reports, we strongly encourage the use of encrypted email. Our PSIRT PGP/GPG public key is available below.

Email
psirt@havsys.com
Public key
-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGohsawBEADU8hvD84SikfIlklHO8T6kqedM5TehvQXBXePMPJ6ruWhvmsuM
aEYAJE+dsoPGLk7SQOy47Hti/+JeR88q1q5VnQtilP6AMSZBQMqgfcqj9GFPuGTM
5PhsrsQEaRIYzTc3InBUj0q882ucwExrlIlTp2pNGSOBmKJw4Fvh2AyfAvQf6ERP
JJgU7sM3VfSoAcQBtgVs608g8qeomx6gt1MK83zBPB/mMXWfB48e2rmoQNnzH0mM
z2UdgDr16nh9cKEDlKdLKwojT0g1h6Nn1yfGSeBEHgJhCtiUn7Y9sBnUetIuTe99
+TqbiVb8nUnAMI3pfgEm/FPXYVDyzZEUW0kLyvdc6FjvIvbV7iqfPnnb0i6tt8M+
hzAHFWPjVehBBKTUw4Dyis6mhRtseTQHVdIx8/8Jc/WouaPLe/5jacO+WFzFb9pg
uHM+t6l2C6FKfU8xrJotLNR7XLWpJkAq4VbiXwcRyZ+im5VFXgoAd+vQtiXnGOvb
Lxcz7fJT1jj+UYxcPLyvdXPfkYjttUKtaJNsM35ry4f6zXa7GBeAkE18WTak+WUB
naIFlg29nqIkrpzPnWNA8+KEtENazyVFAeyxEqJwsIaw8Y4V+hz1MGErOcEGomjN
wUKPLBPVX1BfWTovzyJl2oqdK0aOhFDI2t5JoRH2mFwSHfnZC3VvzXd1kwARAQAB
tE9IYXZlcmZvcmQgUFNJUlQgKENWRSBDb29yZGluYXRpb24gZW1haWwgZm9yIEhh
dmVyZm9yZCBQU0lSVCkgPHBzaXJ0QGhhdnN5cy5jb20+iQJUBBMBCgA+FiEEVmA4
NxcqS9e8NoNHoWm5lazjoqIFAmohsawCGwMFCQPCZwAFCwkIBwIGFQoJCAsCBBYC
AwECHgECF4AACgkQoWm5lazjoqIMjRAApkqysb9ktH1qLGi7Li2rIwiNbhqjtsW3
lXRhkzZ+zVZ64QKfGosyvJ445IbOvLGwnF3gylM7Q5bWhL1rIKTF52bFQSyVuqcM
H5maIBUdk+r0hHeOoq5P6a4z+XrzkH8ccdt4OWmtFAocipBc3SN0i34csJzQTGR/
pY4nJP3vSEVzuX41r878ArnBhPIHhKoQOxTsZM7bk1eKp/aKyY8xL5NevzZrtduQ
xyBr4IpQKpvyLxXbSPd395fw4xkabNTQB72yzaZqDQ0+DVZLCuJQDJErtGiZAOp0
GxtbPBlDtvnkPR+ipS3nDa/apZoagNP4DUN7UkgJ2uhiCEKNR9Z36jX7V8oTa/n6
drHtZ8ZSjk16IFFCBVKANwXYRVlK8+sE9HH648F2eBBIIBaQlXGlUiKEuQRPQmBc
GJ08H0kHMOmqgbbN81bAUNa+xeEMTNQ5zp0K0aFLkXOKR6csZVVEuZlqeXZVPg3O
hXw3laENoGlAMLmV1fCWXkN/RlALVqQe0HH+P/jqBNIGKRbhD1tbAy9NufH6PHlN
5Nswgq66TYe/CIwtCcXg3ccSd78fNWaWUpNoGGW8GpNGB4jWEtFcknDgg9ODuC7B
Zs2e2ODzw0ddboQOG92JHybO/8mbQvl11kZE/IcbykkayXB8Nk58IXpUKckV8lDB
vuBwGF/Ziqm5Ag0EaiGxrAEQAO26pYwHM7Yb0bsjKA15aIdrwjGnm5WcUa26lRMb
qD06fFHNFAz2eKuSXphm1Y+y4OFkbg7l7wMI5w8HGS5PN2ZPJvOzdRHWE3sOFCpW
Ndf53qI+EO3rzTxfcyn11WxvXXOfGOKff/2NEoi0rrwun/vT2n4n63zS2qwTqRzm
2utsnnOKrsQltO6nBzZMJG2a1IoSGhTasesIN7wJMVLLsz3dYCX6Yf9H7kC03/UF
GPTH8GnEaJXPrSBjnTX5f5SplyTuejldeBx6mnTq3yCc8oN0Wo9qQmWTWknT/2tS
cxRhtlAPIqmK/lu8yKzfcm9Vmy6FQEGN/SWO2wEMkZuo0YquoX8kg7gfYXS0K2Hi
83OjqCkmGMTyRmbke8sfwzqU61XCWbYVsRHhJTphX3BeaC1ygxqMB9Skrs6vquUU
oNit+UoZU1EWr7kvzSk2/oOTa5YnDcdTMTYsVqeRVq5xQvkPczPhASK2gGPGYheQ
hxonJrVGrinjgeu8o21Os+0wkZcGj88xpIUr95JuN19DKV/nCtM79z+Pnyum4tGZ
yvXo71owIslkVPlRLJgjsZki+uTlG2JY/kbPTEV2gcyMpwuTXlZnq14HdRkM4EYi
ijOVrnREIoyIIWv8h/RSmKk/FNeyOj1erqfOQ6k3JLGmQPpNJhjDEb5++XUBxLJA
jaoPABEBAAGJAjwEGAEKACYWIQRWYDg3FypL17w2g0ehabmVrOOiogUCaiGxrAIb
DAUJA8JnAAAKCRChabmVrOOiollDEACJCghFg1hEli+L+JUAjNMD2nxtgTCRlVbk
4Pz1ioZ1GYBF4CIdSU3WAc/fYFQoafjz89JAk9nju7LGzOQGkxc0YHHof8hKlaF1
7V//tIGL2+1y0GtkYfROmmlFel1j5/QnrpuLCycfh3IxlhgJFyWA9SKa39evrBP6
Bh7R/XC1flkcvDc5Jno62eIsxO22XZ8CrZuqwun6vGmMF5lo1WMHwDYsrwWFqO3K
9WP+KzGTwjO85+g88OL0Ji9aRo/mC8V827B0Rehof47dUoT3EWPpz1okeIEReDWL
pdvPIOu8q/OHiY5wGRlB9VXldUJpq6Zw0eOrHxTqMJeqZ1Ko6/bcZvJljpldTjHv
/Ljjl4Y4G29Kr+iIYUnKg+vaFHdJ83NzsyVyVOcCC6OkHszDYymto+Tolehajl/R
GnqA9o4PZS767bYUofdD9r4qEd0WHkamHTZ4CHVQ8aoJudxUTy3rtZs25QpwHzs2
B7bkZlMpEaovZi4ov2BhYlWEpomUcBtIxyIfbb33vHFjxEg1kuynVPLaoqVUoFhX
hrj3aArYFPhQDXc+EgYAGaPQ85Rn8qlK0AqfEv0lc+DleyDkcq2WW/KNP0BrmWQ7
HgAqTypSKPtMavWHHW976ZbOJlX57qRY2gOG1H6Wznzu3+S3gPPbe0T6GLu3R2ST
QqSwUk3W2w==
=WX9q
-----END PGP PUBLIC KEY BLOCK-----
Download haverford-psirt-public-key.asc

Note: Encrypted submissions help protect the confidentiality of vulnerability details prior to remediation. Please use our public key when transmitting sensitive technical information.

Disclosure Policy

Read the full Haverford PSIRT Disclosure Policy (PDF)

What to Include in a Report

To help us triage and investigate your report efficiently, please provide as much of the following information as possible:

  1. Affected product and version — the name and version of the Haverford product or service where the vulnerability was found.
  2. Vulnerability type — e.g., SQL injection, buffer overflow, authentication bypass, use-after-free.
  3. Description — a clear explanation of the vulnerability, including the component or endpoint affected.
  4. Steps to reproduce — a minimal, reliable reproduction procedure that allows our engineers to verify the issue.
  5. Proof of concept — code, scripts, screenshots, or logs that demonstrate the vulnerability (optional but encouraged).
  6. Impact assessment — your assessment of the potential impact, including affected data, systems, or users.
  7. Suggested fix — if you have a recommendation for remediation, we welcome it.
  8. Your contact information — so we can follow up with questions and coordinate disclosure credit.

You may submit reports anonymously; however, anonymous reports limit our ability to follow up or provide attribution.

© Haverford Systems, Inc. All rights reserved. — PSIRT contact: psirt@havsys.com