Can we Assist you?
Please feel free to contact us.

Coordinated Vulnerability Disclosure (CVD) Policy

Elementar Analysensysteme GmbH — last updated 2026-06-18

 

Elementar Analysensysteme GmbH takes the security of its products and services seriously. We welcome reports from security researchers and the wider community and are committed to handling them in a coordinated and transparent manner, in line with the EU Cyber Resilience Act (Regulation (EU) 2024/2847) and good industry practice.

1. Scope

This policy applies to all products, services and online systems operated by Elementar Analysensysteme GmbH.

2. How to report a vulnerability

If you believe you have found a security vulnerability, please contact us:

Please include enough information to reproduce the issue: affected product/version, a description of the impact, and step-by-step instructions or a proof of concept.

3. What you can expect from us

  • We will acknowledge your report within 5 business days.
  • We will keep you informed about our progress as we triage and remediate the issue.
  • We aim to remediate confirmed vulnerabilities and coordinate public disclosure within 90 days, working with you on the timeline where possible.
  • With your permission, we are happy to credit you once the issue is resolved.

4. Our commitment to you (Safe Harbor)

Elementar Analysensysteme GmbH will not pursue or support legal action against researchers who, in good faith, discover and report vulnerabilities in accordance with this policy. We consider security research conducted under this policy to be authorized. Please act in good faith, avoid privacy violations, data destruction and service disruption, and only interact with accounts you own or have explicit permission to test.

5. Out of scope

Findings that require physical access, social engineering of our staff, denial-of-service (DoS/DDoS) attacks, or reports from automated scanners without a demonstrable impact are generally considered out of scope.

6. Our response & reporting structure (PSIRT)

Elementar Analysensysteme GmbH operates an internal Product Security Incident Response Team (PSIRT) that triages reports, coordinates fixes and manages disclosure. Under the EU Cyber Resilience Act, once an actively exploited vulnerability is reported through this channel or discovered internally, statutory reporting deadlines apply from September 2026:

  • Within 24 hours: submit an early warning to the national CSIRT (BSI (Germany)) and ENISA.
  • Within 72 hours: submit a more detailed notification including an initial technical assessment and available mitigations.
  • Within 14 days of a fix: submit the final report once a security update (patch) has been made available.

These statutory deadlines complement — and do not replace — the coordinated timeline we agree with the reporter for public disclosure.

Can we Assist you?
Please feel free to contact us.