Skip to main content

Coordinated Vulnerability Disclosure Policy

Eilersen Electric A/S takes the security of our products seriously. We welcome reports from security researchers and users who identify potential vulnerabilities in our products with digital elements, and we are committed to working with the reporting party to understand and resolve issues quickly.

Reporting a Vulnerability

If you believe you have found a security vulnerability in an Eilersen product, please report it to:

security@eilersen.com 

Please include as much of the following as you can:

  • Product name/model and firmware version
  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue, or a proof-of-concept if available
  • Your contact details, if you wish to be kept informed or credited

What to Expect

  • Acknowledgement of your report within 5 business days
  • Regular updates as we investigate and work on a resolution
  • A target of releasing a fix or mitigation within 90 days of confirming the issue. Embedded and industrial products can require longer validation and rollout than pure software — if that applies, we will let you know and explain the expected timeline
  • Once a fix is available, we will publish information about the vulnerability, affected products, and remediation steps

Coordinated Disclosure

We ask that you give us the opportunity to investigate and address a reported vulnerability before disclosing it publicly. We request that details are not shared publicly until a fix is available or 90 days have passed since our acknowledgement of your report, whichever comes first. If a report is submitted via a CSIRT designated as coordinator, we will work with that CSIRT on the timeline for disclosure.

Safe Harbor

We consider security research conducted in good faith, in accordance with this policy, to be authorised. We will not pursue legal action against researchers who make a genuine, good-faith effort to comply with this policy, including avoiding privacy violations, data destruction, or service disruption during testing.

Recognition

With your permission, we are happy to publicly credit researchers who report valid vulnerabilities when we publish the corresponding fix. Eilersen does not currently operate a paid bug-bounty programme.

Scope

This policy applies to Eilersen Electric A/S products with digital elements, including embedded firmware and connected hardware. It does not cover third-party products, services, or websites not operated by Eilersen.