Effective Date: April 6, 2026
GemBox Ltd. is committed to responding quickly and responsibly to security incidents and reported vulnerabilities affecting its products, website, internal systems, or related business operations.
This page explains how security issues can be reported, how GemBox handles reported or suspected security issues, and who is responsible for coordinating the response.
This policy applies to all GemBox products, including all .NET and JavaScript software components distributed by GemBox.
This policy also applies to the public website www.gemboxsoftware.com, internal company accounts and employee and contractor devices (whether owned by Gembox or the individual), code repositories, build and release systems, and related business systems relevant to the security of GemBox products or operations.
Product issues and bugs that are not security-related should be reported to technical support:
https://support.gemboxsoftware.com/new-ticket
A security incident or vulnerability is any event, weakness, or activity that may negatively affect the confidentiality, integrity, or availability of GemBox products, systems, or data.
Examples include:
Security incidents or suspected vulnerabilities may be reported by email to:
Please use a clear subject line such as:
To help GemBox analyze the report quickly, please include where possible:
GemBox follows a coordinated vulnerability disclosure approach.
After becoming aware of a reported or suspected vulnerability, GemBox will review the issue, assess whether it is security-related, determine severity and scope, and decide on appropriate containment, remediation, and communication steps.
Where appropriate, GemBox will coordinate with the reporter regarding validation, remediation timing, and later public communication.
GemBox asks that reporters act in good faith and avoid actions that would unnecessarily disrupt services, harm customers, or access, modify, or disclose data beyond what is necessary to demonstrate the issue.
After becoming aware of a reported or suspected incident or vulnerability, GemBox will:
GemBox will analyze the issue as early as reasonably possible.
This analysis may include:
Where complete information is not yet available, GemBox will make an initial good-faith assessment based on the information available at the time and will refine that assessment during the investigation.
Depending on the incident or vulnerability, GemBox may:
Where a third-party service provider or dependency is involved, GemBox may coordinate with that provider while remaining responsible for handling the issue as it affects GemBox products and operations.
If an incident or vulnerability materially affects customers, GemBox will provide reasonable notice and guidance through appropriate channels, such as email, support communication, release notes, or website announcements.
Where required by applicable law, GemBox will make mandatory regulatory notifications.
Where a reported or discovered issue falls under a mandatory reporting obligation with a defined legal timeline, GemBox will follow that timeline and maintain a process intended to support timely reporting.
Josip Kremenic, a director and co-owner of GemBox Ltd., is responsible for coordinating security incident response and making final decisions.
If Josip Kremenic is unavailable, Marko Kozlina will act as backup coordinator and decision-maker.
Specific technical, operational, communication, or remediation tasks may be delegated to employees or independent contractors as needed.
Published security notices and incident updates, if any, will be listed at:
https://www.gemboxsoftware.com/company/security-incidents
This policy will be reviewed periodically and updated when needed to reflect changes in products, operations, legal requirements, or security risks.