Sign up for a Changi Account to receive the latest updates
Vulnerability Disclosure Policy
The safety and security of our stakeholders’ data (including customers, employees, partners and suppliers), and the reliability of our products and services, are important to Changi Airport Group (S) Pte. Ltd. (“CAG”). Therefore, we aim to design and develop products and services with high levels of security and reliability. Despite our best efforts, due to the complex and sophisticated nature of our products and services, vulnerabilities and errors may still be present. CAG’s vulnerability disclosure program is part of our efforts to enhance its cybersecurity posture, especially as it relates to our products and services. This VDP describes CAG’s vulnerability disclosure program and sets out CAG’s approach to requesting and receiving reports related to potential vulnerabilities and errors in our products and services. This VDP also outlines the terms and conditions for responsible vulnerability reporting.
Products and services in this VDP refer to digital products and services provided by CAG through [https://www.changiairport.com and https://www.ishopchangi.com/].
Please note that CAG’s vulnerability disclosure program does not authorise, permit or endorse the taking of any action which may contravene applicable laws and regulations such as the Computer Misuse Act 1993. For the avoidance of doubt, any attempt to exploit or test suspected vulnerabilities such as by gaining unauthorised access to any computer/data is strictly prohibited, and neither permitted nor encouraged.
To report a vulnerability, please click on the ‘Submit a report’ button at the bottom of this page. Please note that reporting any vulnerability or error (including supplying your personal data and contact information) is entirely voluntary. By submitting a report, you hereby consent for your personal data (including your name, email address) to be collected, used and/or disclosed by members of the CAG Group to assess the report that you have submitted and for the purposes set out in Changi Airport Group (Singapore) Pte. Ltd.'s (CAG) Privacy Policy.
TERMS AND CONDITIONS
By submitting a report to CAG, or otherwise communicating to CAG regarding any vulnerabilities and errors, you agree that:
CODE OF CONDUCT FOR PARTICIPANTS OF CAG’S VULNERABILITY DISCLOSURE PROGRAMME