Contact PSIRT

The Nozomi Networks Product Security Incident Response Team (PSIRT) accepts vulnerability reports, compliance concerns, and other sensitive security matters from researchers, partners, customers, and the public.

To protect your submission, your message and every file attachment are encrypted in your browser with our public GPG key before they are transmitted. Only the PSIRT private key holder can decrypt them. You can review the public key on the PSIRT GPG key page.

Prefer email? Send an encrypted message to prodsec@nozominetworks.com using our GPG key.

Use this form to report a security vulnerability, compliance concern, or other sensitive matter. Your message and all file attachments are encrypted in your browser with the Nozomi Networks PSIRT public GPG key before they leave your computer, so the server only ever receives ciphertext that the PSIRT private key holder can read. Your name and email address are the exception: they are sent over HTTPS in plaintext, because we need them to acknowledge your report and reply to you.

Drag and drop files here

Optional supporting files (e.g. evidence, PoC, encrypted archives). Drag and drop is supported. Each file is encrypted in your browser before upload, which adds about a third to its size, so the limit is 3.5 MB in total before encryption.