Coordinated Vulnerability Disclosure Policy
Eilersen Electric A/S takes the security of our products seriously. We welcome reports from security researchers and users who identify potential vulnerabilities in our products with digital elements, and we are committed to working with the reporting party to understand and resolve issues quickly.
Reporting a Vulnerability
If you believe you have found a security vulnerability in an Eilersen product, please report it to:
Please include as much of the following as you can:
- Product name/model and firmware version
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue, or a proof-of-concept if available
- Your contact details, if you wish to be kept informed or credited
What to Expect
- Acknowledgement of your report within 5 business days
- Regular updates as we investigate and work on a resolution
- A target of releasing a fix or mitigation within 90 days of confirming the issue. Embedded and industrial products can require longer validation and rollout than pure software — if that applies, we will let you know and explain the expected timeline
- Once a fix is available, we will publish information about the vulnerability, affected products, and remediation steps
Coordinated Disclosure
We ask that you give us the opportunity to investigate and address a reported vulnerability before disclosing it publicly. We request that details are not shared publicly until a fix is available or 90 days have passed since our acknowledgement of your report, whichever comes first. If a report is submitted via a CSIRT designated as coordinator, we will work with that CSIRT on the timeline for disclosure.
Safe Harbor
We consider security research conducted in good faith, in accordance with this policy, to be authorised. We will not pursue legal action against researchers who make a genuine, good-faith effort to comply with this policy, including avoiding privacy violations, data destruction, or service disruption during testing.
Recognition
With your permission, we are happy to publicly credit researchers who report valid vulnerabilities when we publish the corresponding fix. Eilersen does not currently operate a paid bug-bounty programme.
Scope
This policy applies to Eilersen Electric A/S products with digital elements, including embedded firmware and connected hardware. It does not cover third-party products, services, or websites not operated by Eilersen.
