Vulnerability Disclosure Policy


This page describes the methodology of Harry Winston Inc. to receiving reports describing vulnerabilities identified on this website.

Customers, users, researchers, partners and any other person that interacts with the products and services of Harry Winston Inc. are encouraged to report identified vulnerabilities and errors. The standard method to submit vulnerability reports to Harry Winston Inc. is to send an email to the dedicated email address: responsibledisclosure@harrywinston.com.

The Terms of Use and the Privacy Policy of Harry Winston Inc. apply, except where stated otherwise.

Please note that supplying your contact information with your report is entirely voluntary and at your discretion. If you do submit your contact information, Harry Winston Inc. will only use it to process your report and to get in touch with you, if necessary.

Harry Winston Inc. may use your report for any purpose deemed relevant by Harry Winston Inc. To the extent that you propose any changes and/or improvements to a product or service in your report, you assign to Harry Winston Inc. all use and ownership rights to such proposals.

By submitting a vulnerability report to Harry Winston Inc., you further agree to the following terms:

  • You have not exploited or used in any manner, and will not exploit or use in any manner (other than for the purposes of reporting to Harry Winston Inc.), the discovered vulnerabilities and/or errors;
  • You have not engaged, and will not engage, in testing/research of systems with the intention of harming Harry Winston Inc., its assets, customers, employees, partners or suppliers;
  • You have not used, misused, deleted, altered or destroyed, and will not use, misuse, delete, alter or destroy, any data that you have accessed or may be able to access in relation to the discovered vulnerability and/or error;
  • You have not conducted, and will not conduct, social engineering, spamming, phishing, denial-of-service or resource-exhaustion attacks;
  • You agree not to disclose to any third party any information related to your report, the vulnerabilities and/or errors reported, nor the fact that a vulnerabilities and/or errors has been reported to Harry Winston Inc.;
  • Harry Winston Inc. does not guarantee that you will receive any response related to your report. Harry Winston Inc. will only contact you regarding your report if it is deemed necessary;
  • You agree that you are making your report without any expectation or requirement of reward or other benefit, financial or otherwise, for making such report, and without any expectation or requirement that the vulnerabilities and/or errors reported are corrected by Harry Winston Inc.