Code of Business Conduct and Ethics
Export Control Information
Kitware, Inc. is based in the United States of America and all products are developed in the U.S or via online collaboration in public forums and distributed from within the U.S. As a result, U.S. export laws and regulations apply to Kitware’s product distribution and remain in force as products and technology are re-exported to different parties and places around the world.
IF YOU EXPORT KITWARE PRODUCTS, YOU ARE RESPONSIBLE FOR COMPLYING WITH THE REQUIREMENTS OF THE BUREAU OF INDUSTRY AND SECURITY (“BIS”), EXPORT ADMINISTRATION REGULATIONS (“EAR”), OR OTHER U.S. EXPORT LAWS.
Classification Matrix
The Kitware Product and Services Classification Matrix (“Matrix”) is a general listing of Kitware software products and services. The matrix is to be used in conjunction with the Export Administration Regulations (“EAR”) in order to assist our customer’s in the export of Kitware products. All classification information contained in the matrix is subject to change without notice.
The Matrix is not intended to replace the EAR and other U.S. Export laws, but is provided as an accommodation to our customers to be used in conjunction with said laws to assist in the export of Kitware products and services. The exporter is responsible for exporting Kitware products, in accordance with the requirements of the EAR and other U.S. Export laws. End-user, end-use and country of ultimate destination may affect export licensing requirements. All Export Control Classification Numbers (“ECCN”), HTS Numbers and License Authorization information are subject to change without notice. Modification in any way to a Kitware product voids the classification. It is your obligation as an exporter to verify such information and comply with the current applicable regulations.
Kitware makes no warranty or representation that the information contained on this site is accurate, current, or complete. It is your obligation as the exporter to comply with the current applicable requirements of United States export rules and regulations. Any use of such information by you is without recourse to Kitware and is at your own risk. Kitware is in no way responsible for any damages whether direct, consequential, incidental, or otherwise, suffered by you as a result of using or relying upon such information for any purpose.
Reporting a Vulnerability
Kitware takes the security of our software products and services seriously, including all of our managed open source code repositories.
If you would like to report a vulnerability please use these guidelines below.
- Low to moderate severity issues (minor information disclosure, denial of service, or other limited-impact findings) may be reported by opening an issue in this repository and prefixing the issue title with “Security -” . This allows the community to participate in the discussion while keeping the process lightweight for lower-risk findings.
- High severity vulnerabilities (remote code execution, authentication bypass, privilege escalation, or exposure of sensitive data) should be reported privately to oss_security@kitware.com. Please include a description of the issue, steps to reproduce, and any relevant environment details. Do not open a public issue for high severity findings, as this could expose users to risk before a fix is available. We will acknowledge your report in a timely manner and ask that you keep it confidential until a public announcement has been made. If you are unsure whether your finding qualifies as high severity, err on the side of emailing us.
Third-Party Dependencies
If you discover a vulnerability in a third-party library or component that this project depends on, please report it directly to the maintainers of that upstream project. We also ask that you notify us at oss_security@kitware.com so we are aware of the issue and can plan to incorporate any fixes into our own releases.
Supported Versions
Security fixes are applied based on the lifecycle established through the project, though a planned release may be accelerated or a patch release issued in response to a significant vulnerability. We encourage all users to stay current with the latest release. If you are unsure whether a version is still receiving security updates, contact us at oss_security@kitware.com.