FENDI considers its systems, and in particular, personal data, as fundamental assets for the company, for which security and confidentiality constitute an essential factor for the trust of its clients.
Despite a strong focus on security, some vulnerabilities may not be noticed during releases to the public or new ones may emerge.
If you discover a vulnerability regarding the FENDI domains and you want to share it with us, we ask you, in the spirit of responsible disclosure, to send us a report relating to such vulnerability by following this “Responsible Disclosure” policy.
In particular:
Once the report has been received, FENDI will do its utmost to:
The information confidentiality period is considered by FENDI to last until the closure of the vulnerability and to the following report to those who sent the notice.
Notices relating to the following cases are excluded from the present Responsible Disclosure policy and will consequently be rejected without relative validation:
Fendi will process all personal contact information of the reporting individual (name, email and optionally a telephone number) for the sole purposes of managing the follow-up on the report and to carrying out the necessary actions in relation to the vulnerability reported. The personal data of the reporting individual may be communicated to the appropriate authorities and to third party companies that offer us research services in relation to the vulnerability reported.
Fendi expresses its thanks for any reports but clarifies that no reward is offered (monetary or otherwise) for reporting in relation to alleged or identified vulnerabilities.
Fendi reserves the right not to handle reports that do not respect the stipulated requirements in the present Responsible Disclosure policy.
FENDI reserves the right to update at any moment the Responsible Disclosure policy described above.