The Haverford Product Security Incident Response Team (PSIRT) is responsible for receiving, investigating, and coordinating the disclosure of security vulnerabilities in Haverford products and services, including the brands PTZOptics and HuddleCamHD. We work with security researchers, customers, and partners to ensure vulnerabilities are addressed in a timely and responsible manner.
Reporting a Vulnerability
If you have discovered a potential security vulnerability in a Haverford product or service, we encourage you to report it to us promptly. We are committed to working with you to understand, validate, and remediate the issue.
To submit a vulnerability report, use our secure reporting form or send an email to psirt@havsys.com. We request that you practice responsible disclosure and allow us a reasonable timeframe to investigate and address the vulnerability before any public disclosure.
Secure Communication
For sensitive vulnerability reports, we strongly encourage the use of encrypted email. Our PSIRT PGP/GPG public key is available below.
- psirt@havsys.com
- Public key
-----BEGIN PGP PUBLIC KEY BLOCK----- mQINBGohsawBEADU8hvD84SikfIlklHO8T6kqedM5TehvQXBXePMPJ6ruWhvmsuM aEYAJE+dsoPGLk7SQOy47Hti/+JeR88q1q5VnQtilP6AMSZBQMqgfcqj9GFPuGTM 5PhsrsQEaRIYzTc3InBUj0q882ucwExrlIlTp2pNGSOBmKJw4Fvh2AyfAvQf6ERP JJgU7sM3VfSoAcQBtgVs608g8qeomx6gt1MK83zBPB/mMXWfB48e2rmoQNnzH0mM z2UdgDr16nh9cKEDlKdLKwojT0g1h6Nn1yfGSeBEHgJhCtiUn7Y9sBnUetIuTe99 +TqbiVb8nUnAMI3pfgEm/FPXYVDyzZEUW0kLyvdc6FjvIvbV7iqfPnnb0i6tt8M+ hzAHFWPjVehBBKTUw4Dyis6mhRtseTQHVdIx8/8Jc/WouaPLe/5jacO+WFzFb9pg uHM+t6l2C6FKfU8xrJotLNR7XLWpJkAq4VbiXwcRyZ+im5VFXgoAd+vQtiXnGOvb Lxcz7fJT1jj+UYxcPLyvdXPfkYjttUKtaJNsM35ry4f6zXa7GBeAkE18WTak+WUB naIFlg29nqIkrpzPnWNA8+KEtENazyVFAeyxEqJwsIaw8Y4V+hz1MGErOcEGomjN wUKPLBPVX1BfWTovzyJl2oqdK0aOhFDI2t5JoRH2mFwSHfnZC3VvzXd1kwARAQAB tE9IYXZlcmZvcmQgUFNJUlQgKENWRSBDb29yZGluYXRpb24gZW1haWwgZm9yIEhh dmVyZm9yZCBQU0lSVCkgPHBzaXJ0QGhhdnN5cy5jb20+iQJUBBMBCgA+FiEEVmA4 NxcqS9e8NoNHoWm5lazjoqIFAmohsawCGwMFCQPCZwAFCwkIBwIGFQoJCAsCBBYC AwECHgECF4AACgkQoWm5lazjoqIMjRAApkqysb9ktH1qLGi7Li2rIwiNbhqjtsW3 lXRhkzZ+zVZ64QKfGosyvJ445IbOvLGwnF3gylM7Q5bWhL1rIKTF52bFQSyVuqcM H5maIBUdk+r0hHeOoq5P6a4z+XrzkH8ccdt4OWmtFAocipBc3SN0i34csJzQTGR/ pY4nJP3vSEVzuX41r878ArnBhPIHhKoQOxTsZM7bk1eKp/aKyY8xL5NevzZrtduQ xyBr4IpQKpvyLxXbSPd395fw4xkabNTQB72yzaZqDQ0+DVZLCuJQDJErtGiZAOp0 GxtbPBlDtvnkPR+ipS3nDa/apZoagNP4DUN7UkgJ2uhiCEKNR9Z36jX7V8oTa/n6 drHtZ8ZSjk16IFFCBVKANwXYRVlK8+sE9HH648F2eBBIIBaQlXGlUiKEuQRPQmBc GJ08H0kHMOmqgbbN81bAUNa+xeEMTNQ5zp0K0aFLkXOKR6csZVVEuZlqeXZVPg3O hXw3laENoGlAMLmV1fCWXkN/RlALVqQe0HH+P/jqBNIGKRbhD1tbAy9NufH6PHlN 5Nswgq66TYe/CIwtCcXg3ccSd78fNWaWUpNoGGW8GpNGB4jWEtFcknDgg9ODuC7B Zs2e2ODzw0ddboQOG92JHybO/8mbQvl11kZE/IcbykkayXB8Nk58IXpUKckV8lDB vuBwGF/Ziqm5Ag0EaiGxrAEQAO26pYwHM7Yb0bsjKA15aIdrwjGnm5WcUa26lRMb qD06fFHNFAz2eKuSXphm1Y+y4OFkbg7l7wMI5w8HGS5PN2ZPJvOzdRHWE3sOFCpW Ndf53qI+EO3rzTxfcyn11WxvXXOfGOKff/2NEoi0rrwun/vT2n4n63zS2qwTqRzm 2utsnnOKrsQltO6nBzZMJG2a1IoSGhTasesIN7wJMVLLsz3dYCX6Yf9H7kC03/UF GPTH8GnEaJXPrSBjnTX5f5SplyTuejldeBx6mnTq3yCc8oN0Wo9qQmWTWknT/2tS cxRhtlAPIqmK/lu8yKzfcm9Vmy6FQEGN/SWO2wEMkZuo0YquoX8kg7gfYXS0K2Hi 83OjqCkmGMTyRmbke8sfwzqU61XCWbYVsRHhJTphX3BeaC1ygxqMB9Skrs6vquUU oNit+UoZU1EWr7kvzSk2/oOTa5YnDcdTMTYsVqeRVq5xQvkPczPhASK2gGPGYheQ hxonJrVGrinjgeu8o21Os+0wkZcGj88xpIUr95JuN19DKV/nCtM79z+Pnyum4tGZ yvXo71owIslkVPlRLJgjsZki+uTlG2JY/kbPTEV2gcyMpwuTXlZnq14HdRkM4EYi ijOVrnREIoyIIWv8h/RSmKk/FNeyOj1erqfOQ6k3JLGmQPpNJhjDEb5++XUBxLJA jaoPABEBAAGJAjwEGAEKACYWIQRWYDg3FypL17w2g0ehabmVrOOiogUCaiGxrAIb DAUJA8JnAAAKCRChabmVrOOiollDEACJCghFg1hEli+L+JUAjNMD2nxtgTCRlVbk 4Pz1ioZ1GYBF4CIdSU3WAc/fYFQoafjz89JAk9nju7LGzOQGkxc0YHHof8hKlaF1 7V//tIGL2+1y0GtkYfROmmlFel1j5/QnrpuLCycfh3IxlhgJFyWA9SKa39evrBP6 Bh7R/XC1flkcvDc5Jno62eIsxO22XZ8CrZuqwun6vGmMF5lo1WMHwDYsrwWFqO3K 9WP+KzGTwjO85+g88OL0Ji9aRo/mC8V827B0Rehof47dUoT3EWPpz1okeIEReDWL pdvPIOu8q/OHiY5wGRlB9VXldUJpq6Zw0eOrHxTqMJeqZ1Ko6/bcZvJljpldTjHv /Ljjl4Y4G29Kr+iIYUnKg+vaFHdJ83NzsyVyVOcCC6OkHszDYymto+Tolehajl/R GnqA9o4PZS767bYUofdD9r4qEd0WHkamHTZ4CHVQ8aoJudxUTy3rtZs25QpwHzs2 B7bkZlMpEaovZi4ov2BhYlWEpomUcBtIxyIfbb33vHFjxEg1kuynVPLaoqVUoFhX hrj3aArYFPhQDXc+EgYAGaPQ85Rn8qlK0AqfEv0lc+DleyDkcq2WW/KNP0BrmWQ7 HgAqTypSKPtMavWHHW976ZbOJlX57qRY2gOG1H6Wznzu3+S3gPPbe0T6GLu3R2ST QqSwUk3W2w== =WX9q -----END PGP PUBLIC KEY BLOCK-----
Download haverford-psirt-public-key.asc
Note: Encrypted submissions help protect the confidentiality of vulnerability details prior to remediation. Please use our public key when transmitting sensitive technical information.
Disclosure Policy
What to Include in a Report
To help us triage and investigate your report efficiently, please provide as much of the following information as possible:
- Affected product and version — the name and version of the Haverford product or service where the vulnerability was found.
- Vulnerability type — e.g., SQL injection, buffer overflow, authentication bypass, use-after-free.
- Description — a clear explanation of the vulnerability, including the component or endpoint affected.
- Steps to reproduce — a minimal, reliable reproduction procedure that allows our engineers to verify the issue.
- Proof of concept — code, scripts, screenshots, or logs that demonstrate the vulnerability (optional but encouraged).
- Impact assessment — your assessment of the potential impact, including affected data, systems, or users.
- Suggested fix — if you have a recommendation for remediation, we welcome it.
- Your contact information — so we can follow up with questions and coordinate disclosure credit.
You may submit reports anonymously; however, anonymous reports limit our ability to follow up or provide attribution.