Cyber Resilience Act – Vulnerability Reporting

Instrument Systems takes reports of potential security vulnerabilities in its own products, systems, and digital services seriously. If you have discovered a vulnerability, we ask that you report it to us confidentially.


Purpose of this page
 

This page explains:

  • how to submit a security-related report to Instrument Systems,
  • what information is helpful for an efficient assessment, and
  • how Instrument Systems handles incoming reports.
     


Scope
 

This reporting information applies to potential vulnerabilities in:

  • Instrument Systems products,
  • associated software, firmware, and embedded components, and
  • digital services, web applications, and interfaces provided or operated by Instrument Systems.

If you are unsure whether your report falls within this scope, please send it to the contact listed below anyway.
 



Contact for vulnerability reports
 

Please send your report to the following central contact address:

vulnerability@instrumentsystems.com

Preferred languages: English or German.
 



Helpful information for your report
 

The more complete your information, the faster we can review and assess your report. Where possible, please let us know:

About the affected product or system:

  • Name of the affected product, system, or service (including serial number, if applicable)
  • Affected version, configuration, and component

About the vulnerability itself:

  • Description of the vulnerability and the observed behavior
  • Technical impact on confidentiality, integrity, availability, or other security-relevant properties
  • Steps to reproduce

About exploitability (if known):

  • Known attack methods, interfaces, or mechanisms of exploitation
  • Required preconditions and the scope of exploitation in your environment

Evidence and contact:

  • Available evidence, such as screenshots, log excerpts, or a proof of concept
  • Your contact details for follow-up questions (if desired)
  • Information on any disclosure already made or planned (if applicable)

Further information on the processing of personal data in connection with vulnerability reports can be found in our Privacy Policy.
https://www.instrumentsystems.com/en/privacy-policy
 


 

What happens after you submit a report
 

Incoming reports are handled confidentially to the extent permitted by law and processed according to a defined internal procedure. Specifically, this means:

  1. Your report is documented and reviewed and assessed by the responsible internal parties.
  2. If we have follow-up questions, we will contact you via your provided contact details. Without contact information, no follow-up can be provided.
  3. For confirmed vulnerabilities, we initiate appropriate remediation measures.
  4. If contact details are available, we will inform you once the vulnerability has been remediated.
     


Response times
 

Where contact details are provided, Instrument Systems aims to provide an initial, non-automated response within five business days.

Further processing time depends on the complexity, reproducibility, and technical impact of the reported vulnerability. If more time is needed, we will inform you where possible as the process progresses.
 


 

Coordinated Vulnerability Disclosure
 

Instrument Systems supports a coordinated approach to handling vulnerability information. We ask reporters to:

  • keep information about the vulnerability confidential initially, and
  • make any public disclosure only after appropriate coordination with us.
     

 

Confidentiality and responsible conduct
 

Please act responsibly when submitting your report and avoid unnecessary disruption to systems, data, or third parties. Specifically, we ask that you:

  • limit testing to the extent necessary to verify the vulnerability,
  • do not alter, delete, or access data without authorization,
  • do not disrupt systems, services, or third parties, and
  • do not disclose information publicly without prior coordination.

If the vulnerability is already publicly known or an active attack appears to be underway, please indicate this in your report.
 



Not for general inquiries
 

This contact channel is intended exclusively for reporting vulnerabilities.

For general support requests, service cases, product questions, or sales inquiries, please use Instrument Systems' regular contact channels.

 


 

Further information
 

Coordinated Vulnerability Disclosure (CVD) Policy

security.txt

The security.txt file contains Instrument Systems' published contact and reporting information for security matters in a standardized, machine-readable format. It supplements this page and is particularly relevant for automated security research.