Skip to content

Vulnerability Disclosure Policy

Unilever is committed to safeguarding and protecting our information and any other information entrusted to us.

This means we take cyber security issues very seriously and recognise the importance of privacy, security, and community outreach. As such, we are committed to addressing and reporting security issues through a coordinated and constructive approach; designed to drive the greatest protection for technology users and protection of Unilever information along with information relating to our customers, consumers and employees.

When properly notified of legitimate issues, we will do our best to acknowledge your vulnerability report, assign resources to investigate the issue, and fix potential problems as quickly as possible. Whether you are a user of Unilever products, a software developer, or simply a security enthusiast, you are an important part of this process.

Reporting security issues

If you believe you have discovered a vulnerability in a Unilever asset / system or have a security incident to report, please send an email to Cyber.VDP@unilever.com.

In all cases, you must:

  • Respect our privacy. Contact us immediately if you access anyone else’s data, personal or otherwise. This includes usernames, passwords and other credentials. You must not save, store or transmit this information.
  • Act in good faith. You should report the vulnerability to us with no conditions attached.
  • Work with us. Promptly report any findings to us, stopping after you find the first vulnerability and requesting permission to continue testing. Allow us a reasonable amount of time to resolve the vulnerability before publicly disclosing it.

And you must not:

  • Exfiltrate data. Instead use a proof of concept to demonstrate a vulnerability.
  • Exploit a vulnerability to disable further security controls.
  • Perform social engineering.
  • Use automated scanners.

Next Steps

  • Confidentiality: We request that you keep all communications regarding the vulnerability confidential until the issue has been resolved.
  • Acknowledgement: We aim to acknowledge receipt of your report within five business days.
  • Triage: Our internal security team will investigate and validate the vulnerability. Please note that, in the event of duplicate reports for the same vulnerability, we will recognise only the first complete report received in our inbox.
  • Remediation: We will work to address the vulnerability and apply any necessary patches or fixes. The time required for resolution will depend on the severity and complexity of the issue.
  • Recognition: Successful vulnerability reports will receive recognition and a thank you email in appreciation of the security researcher’s contribution to improving the security of our platforms.

We greatly appreciate the efforts of security researchers and discoverers who share information on security issues with us, giving us a chance to improve our products and services, and better protect our customers. Thank you for working with us through the above process.

Back to top