Coordinated Vulnerability Disclosure Policy
Introduction
We take the security of our products seriously. This Coordinated Vulnerability Disclosure (CVD) Policy describes how security researchers, customers, and third parties can report potential security vulnerabilities in our products or services. This policy is established in accordance with the EU Cyber Resilience Act (CRA) requirements for coordinated vulnerability disclosure.
Scope
The policy applies to products or components of products manufactured or maintained by Schmid Elektronik AG.
This includes:
- Firmware
- Software
- Cloud services
- Web interfaces
- APIs
Reports concerning vulnerabilities in third-party components incorporated into our products are also welcome. Where appropriate, we will coordinate with the relevant component supplier or maintainer.
Reporting a Vulnerability
If you discover a potential security vulnerability, please report it to us using one of the following channels:
- Primary contact: https://schmid-elektronik.ch/security-vulnerability-report-form/
- security.txt: https://schmid-elektronik.ch/.well-known/security.txt
Please include the following information where possible:
- Product name and version
- Software version
- Description of the vulnerability
- Steps to reproduce
- Your contact information
Reporters may request an embargo period (typically up to 90 days)
We may request extensions if a fix requires more time
Guidelines
We ask that you:
- Do not publicly disclose the vulnerability before coordination
- Avoid accessing personal data unnecessarily
- Avoid disrupting services or damaging systems
- Do not conduct social engineering, spam, or phishing attacks (unless mutually agreed)
- Act in good faith
We will not take legal action against researchers who follow this policy, act in good faith and respect applicable laws.
Our Commitments
When you report a vulnerability, we commit to:
- Acknowledge receipt within 5 working days
- Keep you informed about remediation progress
- Coordinate public disclosure where appropriate
Contact
Primary contact: https://schmid-elektronik.ch/security-vulnerability-report-form/
Policy Updates
We may update this policy periodically.
Last updated: 11.08.2026