{"id":5388,"date":"2026-04-30T13:01:03","date_gmt":"2026-04-30T12:01:03","guid":{"rendered":"https:\/\/www.withsecure.com\/?page_id=5388"},"modified":"2026-09-15T09:06:52","modified_gmt":"2026-09-15T06:06:52","slug":"vulnerability-reward-program","status":"publish","type":"page","link":"https:\/\/www.withsecure.com\/en\/about-us\/vulnerability-reward-program\/","title":{"rendered":"Vulnerability reward program"},"content":{"rendered":"<section\n    class=\"wp-block-one-column-block edwp-block js-wp-block-one-column-block wp-block-one-column-block--content-1 layout--spacing-xxxxl-top layout--spacing-xl-bottom\"\n    >\n    <div class=\"wp-block-one-column-block__container\">\n                                                                                                                            <div class=\"wp-component-content wp-component-content--default wp-block-one-column-block__content fade-in\">\n            <h1 class=\"wp-component-heading text--h2 wp-component-content__title\">\n    Vulnerability <span class=\"blue-text\">reward program.<\/span><\/h1>                <\/div>                                                                                <\/div>\n<\/section>\n\n\n<section\n    class=\"wp-block-one-column-block edwp-block js-wp-block-one-column-block wp-block-one-column-block--content-1 layout--spacing-xxxl-bottom\"\n    >\n    <div class=\"wp-block-one-column-block__container\">\n                                                                                                                                    <div class=\"wp-component-image__wrapper wp-block-one-column-block__image fade-in\">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"1600\" height=\"637\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Frame-117.jpg.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-content-25-1 wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Frame-117.jpg.webp 1600w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Frame-117-300x119.jpg.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Frame-117-1024x408.jpg.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Frame-117-768x306.jpg.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Frame-117-1536x612.jpg.webp 1536w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Frame-117-447x178.jpg.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Frame-117-367x146.jpg.webp 367w\" sizes=\"auto, (max-width: 1600px) 100vw, 1600px\" \/>                                                    <\/figure>\n                    <\/div>\n                                                                                <\/div>\n<\/section>\n\n\n<section\n    class=\"wp-block-two-column-block edwp-block js-wp-block-two-column-block wp-block-two-column-block--content-1 wp-block-two-column-block__left--align-y-top wp-block-two-column-block__right--align-y-top wp-block-two-column-block--split-50-50 layout--none-top layout--spacing-xs-bottom\"\n    data-block-id=\"block_8cdf3d05a13e44e0ec1e7b9e8fa0b562\"\n    >\n    <div class=\"wp-block-two-column-block__container row-load\">\n                                                        <div class=\"wp-block-two-column-block__left\">\n                                <h2 class=\"wp-component-heading text--h2 wp-block-two-column-block__heading \">\n    Report vulnerabilities.  <span class=\"blue-text\"> Get rewarded for making things safer.<\/span><\/h2>                <\/div>\n                                                <div class=\"wp-block-two-column-block__right\">\n                                <div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p>WithSecure rewards security researchers who responsibly disclose security vulnerabilities in the eligible WithSecure Elements products and services listed below\u2014 also known as a &#8220;bug bounty&#8221; program. If you have found a security issue, we want to hear about it. Read these guidelines in full before participating.<\/p>\n<\/div>\n                <\/div>\n                        <\/div>\n<\/section>\n\n\n<section\n    class=\"wp-block-two-column-block edwp-block js-wp-block-two-column-block wp-block-two-column-block--content-1 wp-block-two-column-block__left--align-y-top wp-block-two-column-block__right--align-y-top wp-block-two-column-block--split-sidebar layout--spacing-xxxl-top layout--spacing-xxxl-bottom\"\n    data-block-id=\"block_3fbd30f6f4812cca612873b196ff33cd\"\n    >\n    <div class=\"wp-block-two-column-block__container row-load\">\n                                                        <div class=\"wp-block-two-column-block__left\">\n                                <nav\n    class=\"wp-component-content-navigation wp-block-two-column-block__content-nav js-content-navigation\"\n    data-bem-base=\"wp-component-content-navigation\"\n    data-nav-column=\"left\"\n    data-nav-type=\"auto\"\n>\n    \n    <div class=\"wp-component-content-navigation__mobile\">\n        <label class=\"wp-component-content-navigation__mobile-label\">\n            <span class=\"wp-component-content-navigation__mobile-label-text\">\n                Content navigation            <\/span>\n            <select class=\"wp-component-content-navigation__select js-content-navigation-select\">\n                <option value=\"\">\n                    Select a section                <\/option>\n                            <\/select>\n        <\/label>\n    <\/div>\n\n    <div class=\"wp-component-content-navigation__desktop\">\n        <div class=\"wp-component-content-navigation__list-wrapper\">\n            <span\n                class=\"wp-component-content-navigation__indicator js-content-navigation-indicator\"\n                aria-hidden=\"true\"\n            ><\/span>\n            <ul class=\"wp-component-content-navigation__list js-content-navigation-list\">\n                            <\/ul>\n        <\/div>\n    <\/div>\n<\/nav>\n                <\/div>\n                                                <div class=\"wp-block-two-column-block__right\">\n                                <div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <h2>What you need to know before you start<\/h2>\n<p>We want to hear about security vulnerabilities in the eligible WithSecure Elements products and services listed below. We offer monetary rewards for eligible reports that are disclosed to us in a coordinated way.<\/p>\n<p>Certain rules must be followed to ensure that your research does not put other users, their data, or our services at risk, and to reduce the likelihood that our monitoring identifies your research as a malicious intrusion attempt. We also want to be clear about how we accept reports and pay rewards.<\/p>\n<p>A &#8220;security vulnerability&#8221; is an issue that causes a breach of the confidentiality, integrity, or availability of a service or data, or causes personal data (personally identifiable information) to be stored or processed in a way that does not comply with current Finnish data protection legislation.<\/p>\n<p>The vulnerability reward program currently covers only the following WithSecure Elements products and their associated Elements cloud services:<\/p>\n<ul role=\"list\">\n<li>WithSecure Elements EPP for Computers (Windows and Mac)<\/li>\n<li>WithSecure Elements EPP for Computers Premium (Windows)<\/li>\n<li>WithSecure Elements EPP for Servers (Windows and Linux)<\/li>\n<li>WithSecure Elements EDR for Servers (Windows and Linux)<\/li>\n<li>WithSecure Elements EPP for Servers Premium (Windows and Linux)<\/li>\n<li>WithSecure Elements EDR for Computers (Windows and Mac)<\/li>\n<li>WithSecure Elements EDR and EPP for Computers (Windows and Mac)<\/li>\n<li>WithSecure Elements EDR and EPP for Computers Premium (Windows)<\/li>\n<li>WithSecure Elements EDR and EPP for Servers (Windows and Linux)<\/li>\n<li>WithSecure Elements Mobile Protection (Android and iOS)<\/li>\n<li>WithSecure Elements Collaboration Protection<\/li>\n<\/ul>\n<p>All other WithSecure products, services, websites, and public web pages are outside the scope of this reward program and are not eligible for rewards. Reports are welcomed, but are outside the reward program.<\/p>\n<p><strong>Supported versions<\/strong><\/p>\n<p>Research must be conducted against the latest generally available version, with the latest database or content updates installed, as released through official WithSecure channels, Google Play, or the Apple App Store.<\/p>\n<p><strong>Reproducibility restrictions<\/strong><\/p>\n<p>Browser-side security issues must be reproducible in an HTML5-capable web browser. Mobile client vulnerabilities must be reproducible on a non-rooted device running the latest manufacturer-provided firmware, which must be no more than one year old. On Android, the device must have Google Play Services factory-installed.<\/p>\n<p>On desktop clients, the issue must be reproducible on an operating system with the latest security patches supplied by the OS vendor or distribution, without the attacker requiring administrator or root access. Eligible client vulnerabilities must be in code that WithSecure delivers as part of the client application. Vulnerabilities in third-party components are generally eligible if those components are delivered as part of the WithSecure client application.<\/p>\n<p>Issues in the underlying platform, operating system, or platform-provided libraries may be eligible if they manifest in or affect an in-scope WithSecure Elements product. For vulnerabilities in external components, we will offer to notify the affected parties in a timely manner. If you need clarification, contact us before beginning your research.<\/p>\n<p><strong>Permissible security research<\/strong><\/p>\n<p>We only allow security research, that:<\/p>\n<ul role=\"list\">\n<li>Makes a good-faith effort to avoid affecting third-party services or their availability;<\/li>\n<li>Makes a good-faith effort not to access, affect, or disclose other users&#8217; accounts, personal data, or content, or affect service availability for other users;<\/li>\n<li>Uses only accounts that belong to you personally\u2014you may create multiple accounts specifically for research under this program;<\/li>\n<li>Targets only accounts, user data, or personal data that belong to you, or uses bogus test data;<\/li>\n<li>Uses or targets clients installed only on hardware that you own and operate;<\/li>\n<li>Uses only methods that comply with your local law and Finnish law;<\/li>\n<li>Does not use malicious or destructive payloads beyond what is technically required for a benign proof-of-concept demonstration; and<\/li>\n<li>Targets only the products and services listed above, subject to the stated exclusions.<\/li>\n<\/ul>\n<p>If you have questions about whether <ins>particular<\/ins> research is permissible or <ins>a<\/ins> target is in scope, contact us at <a href=\"mailto:security@withsecure.com\">security@withsecure.com<\/a> before conducting the research.<\/p>\n<h2>How to report a vulnerability<\/h2>\n<p style=\"text-align: left;\">Submit your report by email to <a href=\"mailto:security@withsecure.com\">security@withsecure.com<\/a>. We strongly recommend encrypting the email using our PGP key, available on key servers, and attaching your own public key. Our PGP key fingerprint is 2622\u00a0 90BA\u00a0 C1DB\u00a0 AB46\u00a0 2954\u00a0 B150\u00a0 1518\u00a0 05EB\u00a0 454B\u00a0 15C4<\/p>\n<p>By submitting a vulnerability report, you grant us a perpetual, worldwide, royalty-free, irrevocable, and non-exclusive license and right to use, modify, and incorporate your submission, or any part of it, into our products, services, or test systems without further obligation or notice to you.<\/p>\n<p>Non-security and non-privacy bug reports and customer service requests sent to this email address will be ignored. For non-security questions about WithSecure products, visit WithSecure Community or contact Support for Business.<\/p>\n<p><strong>Required proof of concept and reproduction details<\/strong><\/p>\n<p>To be eligible for a reward and establish submission priority, your report must include a working, benign proof of concept (PoC) and exact instructions that allow us to reproduce the vulnerability independently.<\/p>\n<p>A working PoC is the smallest non-destructive example that triggers the vulnerability and visibly demonstrates the claimed security impact. Your report must include:<\/p>\n<ul>\n<li>A concise description of the issue, including the expected behavior, the observed behavior, and the security or privacy boundary bypassed;<\/li>\n<li>The exact affected product, component, endpoint, or URI and the tested environment, including applicable version or build numbers, platform, operating system, browser, database version, account role, privileges, configuration, and prerequisites;<\/li>\n<li>A concise, numbered list of steps starting from a clearly stated baseline, with all required commands, requests, parameters, scripts, payloads, files, and other inputs;<\/li>\n<li>The complete PoC materials and instructions for running them, including any required dependencies or setup;<\/li>\n<li>The result that proves successful exploitation and an explanation of the practical security impact; and<\/li>\n<li>If the issue is intermittent, the conditions, timing, and approximate success rate required to reproduce it.<\/li>\n<\/ul>\n<p>For a vulnerability affecting a service, include the date and time in UTC when you reproduced it because the service may have changed since then. For fuzzing findings, also include the initial corpus and the input that triggers the issue.<\/p>\n<p>All information needed to reproduce the issue must be contained in the report and its attachments. Screenshots and videos may be included as supporting evidence, but do not replace the PoC or written reproduction steps. A theoretical description, automated scanner output, version or CVE match, crash log, screenshot, or video alone is not a working PoC.<\/p>\n<p>The PoC must follow the permissible-research rules above and use only accounts, data, and hardware that you own or control. You may also include a suggested fix, but this is optional.<\/p>\n<p>Reports that do not meet these requirements are incomplete and are not eligible for a reward or submission priority. If we cannot reproduce the vulnerability from the information and materials supplied, we cannot reward it.<\/p>\n<p>We aim to acknowledge receipt within five working days. If you do not hear from us by then, please resend the report.<\/p>\n<h2>What happens after your report<\/h2>\n<p>Our developers will determine whether your finding is a security vulnerability and whether we can reproduce it using the information and materials you supplied. If the report qualifies, a reward will be paid after the issue has been fixed.<\/p>\n<p>We cannot commit to a specific fix or payment schedule because each case is different. We give high priority internally to externally reported security issues and aim to keep you updated. You may also request status updates from your case handler.<\/p>\n<p>We may publish the names of people we have rewarded, and if we publish a vulnerability bulletin, we would like to give credit where it is due. If you prefer to use an alias or remain anonymous, we will respect that.<\/p>\n<p>In some cases, we may determine that a reported issue does not pose a security risk or is not a security or privacy vulnerability. No reward will be paid in those cases.<\/p>\n<p>No reward will be paid if the finding is made public in any way before it is fixed. If someone else reported the same issue earlier, we will tell you after the issue has been fixed. If several researchers report the same issue, only the first complete report that includes a working PoC and all information required for independent reproduction is eligible for the reward.<\/p>\n<h2>Payments<\/h2>\n<p>Important: Do not send payment information with your initial report. We will request the appropriate information if and when a payment is due.<\/p>\n<p>Payments are made by bank transfer within the Single Euro Payments Area (SEPA) or by international bank transfer outside SEPA. We cannot use checks, cryptocurrencies, or other money transfer services. The recipient is responsible for transfer charges or fees and for accessing the funds after transfer. Payments are made in euros (EUR) by default, and currency conversions use the current bank rate.<\/p>\n<p>We are required to report rewards paid to individual researchers to the Finnish Tax Administration regardless of where the recipient lives. To make the payment and meet this requirement, we will request your full name, date of birth, current physical mailing address, and bank transfer details. If you have a company, we may ask you to invoice us instead.<\/p>\n<p>The recipient is responsible for any taxes. If you are taxed in Finland, we must collect withholding tax and will require your personal identity number and optionally, your taxation certificate for the current year.<\/p>\n<p>These identification requirements are imposed by the authorities, and we cannot make exceptions. Payments are not made to countries or jurisdictions under embargo or to persons or entities on a sanctions list.<\/p>\n<p>Because of these identification requirements, we deal directly only with the original reporter. We use only the email address from the original report, so ensure that you retain access to that account.<\/p>\n<h2>Further legal statements<\/h2>\n<p>Our lawyers want us to point out the following small print:<\/p>\n<p>You may reverse-engineer and decompile WithSecure clients strictly and solely to conduct security research under this vulnerability reward program. This permission applies only to the WithSecure Elements clients explicitly listed in this program and excludes any licensed third-party components. You may not disclose, show, or publish to any third party any code, or parts of code, derived under this permission in any form.<\/p>\n<p>A description of the personal data record used for reward payments is available <a href=\"https:\/\/www.withsecure.com\/en\/about-us\/vulnerability-reward-program\/personal-data-record\/\">here<\/a>.<\/p>\n<p>WithSecure reserves the right to discontinue this reward program or change its terms at any time without prior notice. This text was last modified on 2026-09-08. The vulnerability reward program currently has no fixed end date. All reward decisions are final. The rules of this program and any related communication do not create or imply any obligation on WithSecure.<\/p>\n<h2>Rewards<\/h2>\n<p>The reward is determined solely by a WithSecure team consisting of technical staff and is based on the estimated risk posed by the vulnerability. The current reward range is EUR 200 to EUR 6,000.<\/p>\n<p>If you report several issues that are duplicates in different parts of a service \u2013 for example, the same code running on different nodes or platforms \u2013 or that form part of a larger issue, we may combine them and pay only one reward.<\/p>\n<p>The following table gives examples of bug classes and their corresponding rewards. It does not cover every possible bug class, but illustrates how severity relates to reward.<\/p>\n<table style=\"border-collapse: collapse; width: 112.199%; height: 902px;\" border=\"1\">\n<tbody>\n<tr>\n<th style=\"width: 40.7332%;\"><strong>Reward<\/strong><\/th>\n<td style=\"width: 101.659%;\"><strong>Example vulnerability classes<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 40.7332%;\">Up to EUR 6,000<\/td>\n<td style=\"width: 101.659%;\">Remote code execution on an Elements production cloud backend; remote file inclusion on an Elements production cloud backend; significant authentication bypass on an Elements production cloud backend containing critical information.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 40.7332%;\">Up to EUR 3,500<\/td>\n<td style=\"width: 101.659%;\">Privilege escalation in an Elements cloud service that grants administrator rights to a low \u2013 privilege user.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 40.7332%;\">Up to EUR 2,500<\/td>\n<td style=\"width: 101.659%;\">Remote code execution in Elements client software; data extraction from an Elements production server; access-control issue exposing personally identifiable information.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 40.7332%;\">Up to EUR 1,000<\/td>\n<td style=\"width: 101.659%;\">Remote code execution within a sandbox; local privilege escalation on a customer machine; persistent denial of service affecting antivirus or privacy functionality.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 40.7332%;\">Up to EUR 350<\/td>\n<td style=\"width: 101.659%;\">Temporary denial of service affecting antivirus functionality; temporary, high-impact denial of service affecting local product functionality.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 40.7332%;\">Up to EUR 200<\/td>\n<td style=\"width: 101.659%;\">Security-related misconfiguration in an Elements production service or client.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n                <\/div>\n                        <\/div>\n<\/section>\n\n\n<section\n    class=\"wp-block-logos edwp-block js-wp-block-logos layout--spacing-xxxl-top layout--spacing-xxxl-bottom\"\n    >\n    <div class=\"wp-block-logos__container\">\n        <div class=\"wp-block-logos__box\">\n            <h2 class=\"wp-component-heading text--h3 wp-component-content__title fade-in\">\n    <span class=\"blue-text\">Trusted solution<\/span> to your security needs<\/h2>            <div class=\"swiper wp-block-logos__swiper js-wp-block-logos-swiper\">\n                <div class=\"swiper-wrapper wp-block-logos__swiper-wrapper row-load\">\n                                            <div class=\"swiper-slide wp-block-logos__slide wp-block-logos__logo\">\n                            <img loading=\"lazy\" decoding=\"async\" width=\"146\" height=\"146\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2025\/11\/Group-811998.png.webp\" class=\"attachment-logo size-logo\" alt=\"\" \/>                        <\/div>\n                                            <div class=\"swiper-slide wp-block-logos__slide wp-block-logos__logo\">\n                            <img loading=\"lazy\" decoding=\"async\" width=\"146\" height=\"146\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2025\/11\/Group-811997.png.webp\" class=\"attachment-logo size-logo\" alt=\"\" \/>                        <\/div>\n                                            <div class=\"swiper-slide wp-block-logos__slide wp-block-logos__logo\">\n                            <img loading=\"lazy\" decoding=\"async\" width=\"146\" height=\"146\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2025\/11\/Group-811999.png.webp\" class=\"attachment-logo size-logo\" alt=\"\" \/>                        <\/div>\n                                            <div class=\"swiper-slide wp-block-logos__slide wp-block-logos__logo\">\n                            <img loading=\"lazy\" decoding=\"async\" width=\"143\" height=\"146\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2025\/11\/SAE3000ii-143x146.png.webp\" class=\"attachment-logo size-logo\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2025\/11\/SAE3000ii-143x146.png.webp 143w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2025\/11\/SAE3000ii.png.webp 288w\" sizes=\"auto, (max-width: 143px) 100vw, 143px\" \/>                        <\/div>\n                                            <div class=\"swiper-slide wp-block-logos__slide wp-block-logos__logo\">\n                            <img loading=\"lazy\" decoding=\"async\" width=\"146\" height=\"146\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2025\/11\/iso27001-146x146.png.webp\" class=\"attachment-logo size-logo\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2025\/11\/iso27001-146x146.png.webp 146w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2025\/11\/iso27001-300x300.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2025\/11\/iso27001-150x150.png.webp 150w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2025\/11\/iso27001.png.webp 400w\" sizes=\"auto, (max-width: 146px) 100vw, 146px\" \/>                        <\/div>\n                                            <div class=\"swiper-slide wp-block-logos__slide wp-block-logos__logo\">\n                            <img loading=\"lazy\" decoding=\"async\" width=\"241\" height=\"200\" src=\"https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/04\/cybersecurity-made-in-europe.svg\" class=\"attachment-logo size-logo\" alt=\"\" \/>                        <\/div>\n                                    <\/div>\n            <\/div>\n        <\/div>\n        <div class=\"wp-block-logos__nav fade-in\">\n            <div class=\"wp-block-logos__pagination js-wp-block-logos-pagination\">\n            <\/div>\n            <div class=\"wp-block-logos__nav-arrow js-wp-block-logos-nav-prev\">\n                <svg class='edwp-icon edwp-icon--reg js-icon ' aria-hidden='true'>\n                <use xlink:href='#chevron'><\/use>\n            <\/svg>            <\/div>\n            <div class=\"wp-block-logos__nav-arrow js-wp-block-logos-nav-next\">\n                <svg class='edwp-icon edwp-icon--reg js-icon ' aria-hidden='true'>\n                <use xlink:href='#chevron'><\/use>\n            <\/svg>            <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n\n\n<section\n    class=\"wp-block-two-column-block edwp-block js-wp-block-two-column-block wp-block-two-column-block--content-1 wp-block-two-column-block__left--align-y-middle wp-block-two-column-block__right--align-y-middle wp-block-two-column-block--split-50-50 layout--spacing-xxxl-top layout--spacing-xxxl-bottom\"\n    data-block-id=\"block_1f9a0e9d1091c790c9b52d5b8d49ca20\"\n    >\n    <div class=\"wp-block-two-column-block__container row-load\">\n                                                        <div class=\"wp-block-two-column-block__left\">\n                                <div class=\"wp-component-content wp-component-content--default wp-block-two-column-block__content \">\n            <h2 class=\"wp-component-heading text--h2 wp-component-content__title\">\n    Personal <span class=\"blue-text\">data record<\/span><\/h2>                    <div class=\"wp-component-content__inner\">\n                                    <div class=\"wp-component-content__content wysiwyg\">\n                        <div class=\"wp-component-paragraph \">\n    <p>How we handle your personal data. <\/p>\n<p>Information on what data are being collected, how we handle personal data, and what your rights as the data subject are.<\/p>\n<\/div>\n                    <\/div>\n                                                                    <div class=\"wp-component-content__buttons\">\n                        <a class=\"wp-component-button btn btn--primary\" href=\"https:\/\/www.withsecure.com\/en\/about-us\/vulnerability-reward-program\/personal-data-record\/\">Learn more<\/a>                    <\/div>\n                            <\/div>\n                <\/div>                <\/div>\n                                                <div class=\"wp-block-two-column-block__right\">\n                                        <div class=\"wp-component-image__wrapper wp-component-image--wrapped wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"600\" src=\"https:\/\/www.withsecure.com\/wp-content\/uploads\/2025\/11\/luminen-ui-ezgif-com-video-to-gif-converter.gif\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-contained\" alt=\"\" \/>                                                    <\/figure>\n                    <\/div>\n                <\/div>\n                        <\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":3,"featured_media":0,"parent":5259,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-5388","page","type-page","status-publish","hentry"],"acf":[],"card":"<div class=\"wp-component-card-insight js-card-link wp-component-card-insight--highlighted\">\n    <div class=\"wp-component-card-insight__image-wrapper\">\n        <img width=\"618\" height=\"440\" src=\"https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder.jpg\" class=\"wp-component-card-insight__image\" alt=\"\" decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder.jpg 618w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder-300x214.jpg 300w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder-447x318.jpg 447w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder-205x146.jpg 205w\" sizes=\"auto, (max-width: 618px) 100vw, 618px\" \/>                    <p class=\"wp-component-card-insight__content-type\">Page<\/p>\n            <\/div>\n    <div class=\"wp-component-card-insight__content\">\n                            <h3 class=\"wp-component-card-insight__title\">Vulnerability reward program<\/h3>\n                                                    <div class=\"wp-component-card-insight__button-wrapper\">\n                <a class=\"wp-component-button btn btn--primary btn--dark wp-component-card-insight__button btn--small\" href=\"https:\/\/www.withsecure.com\/en\/about-us\/vulnerability-reward-program\/\">Read more<\/a>            <\/div>\n            <\/div>\n<\/div>","_links":{"self":[{"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/pages\/5388","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/comments?post=5388"}],"version-history":[{"count":31,"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/pages\/5388\/revisions"}],"predecessor-version":[{"id":13714,"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/pages\/5388\/revisions\/13714"}],"up":[{"embeddable":true,"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/pages\/5259"}],"wp:attachment":[{"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/media?parent=5388"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}