About this role
How to Report Send to: [email protected] - this is our designated single point of contact for vulnerability reports. Out of scope: - Products past end-of-life - DC Airco corporate IT systems (website, email) - Vulnerabilities already publicly disclosed - Customer support requests Our Commitment Response and remediation timelines , scaled to severity: Regulatory Reporting Obligations Where a reported vulnerability is being actively exploited, or results in a severe incident affecting the security of our products, we are legally obligated under Article 14 of the Cyber Resilience Act to notify the relevant national CSIRT (in the Netherlands: the NCSC) and ENISA via the EU Single Reporting Platform, following the statutory timeline: - Early warning within 24 hours of becoming aware - Full notification with technical details within 72 hours - Final report within 14 days (or within 1 month for severe incidents) Where required, we will notify affected customers of actively exploited vulnerabilities and provide guidance on mitigating measures, in parallel with our regulatory notifications. Third-Party Components DC Airco products may include third-party software or hardware components. If a reported vulnerability originates in such a component, we will: - Notify the relevant upstream supplier or maintainer, - Remain responsible for coordinating and delivering a fix to DC Airco customers, even where the underlying flaw lies outside our own codebase, - Where upstream is unresponsive or the component is unmaintained, evaluate mitigation, forking, or replacement of the affected component. Security Advisories Once a reported vulnerability has been resolved, we will publish a security advisory describing: - The affected product(s) and version(s), - A description of the vulnerability and its impact, - A severity rating (e.g. CVSS score), - Remediation guidance, including how to obtain and apply the update. Advisories will be delayed onl...