Vulnerability or Security Incident

PRODUCT SECURITY POLICY — AUTOMATIC SYSTEMS

Report a vulnerability or security incident

Automatic Systems takes the security of its products and systems seriously. If you are a customer, integrator, or security researcher and believe you have identified a vulnerability or security incident affecting one of our products, please notify us using the methods below.

PSIRT Contact Point

Acknowledgment:
within 1 business day
What we ask of you

To help us process your report quickly and efficiently:

  • Describe the vulnerability as precisely as possible: product, version, affected configuration, and steps to reproduce it.
  • Allow us a reasonable amount of time to analyze and fix the issue before any public disclosure.
  • Act in good faith: do not access data that does not belong to you, do not disrupt our services, and limit your testing to what is strictly necessary to demonstrate the vulnerability.
  • Do not test on production installations belonging to our customers without their explicit consent.

Reports made under these conditions will not be subject to any legal action on our part.

Our commitment

Once your report is received, here is the process we follow:

Within 1 business day
Acknowledgment of receipt with a contact point and tracking number.
Within 24 hours, 24/7
Initial severity triage, particularly to determine if the report involves active exploitation or a serious incident.
Within 15 business days
Comprehensive assessment: detailed confirmation of the vulnerability, final severity level, and affected products/versions.
Depending on severity
Development and deployment of a patch or mitigation measure, with notification to affected customers.
After remediation
Publication of a security advisory summarizing the vulnerability and the fix, and acknowledgment of the reporter (unless requested otherwise).
Actively exploited vulnerability or ongoing incident?
Please indicate this explicitly in your message and, if possible, also call your usual sales or support contact. This type of report triggers an internal priority procedure, including our regulatory notification obligations.
Scope
Status Scope Description
In Scope Automatic Systems products, embedded software, applications, and web interfaces currently commercialized or under support.
Out of Scope Third-party infrastructure or services, end-of-support products, social engineering, denial-of-service attacks. Please contact the relevant third party directly if applicable.

How to report

For now, all reports must be sent by email to the dedicated address psirt@automatic-systems.com.

Please include as much of the following as possible:

  • The product, product line, or software module concerned, as well as the installed version or firmware.
  • A description of the vulnerability and its potential impact.
  • Steps to reproduce it, as detailed as possible.
  • Your severity estimate: critical (suspected or proven active exploitation, ongoing incident) or non-critical.
  • Your contact details (name or pseudonym, email) for follow-up.

Do not send executable files or potentially malicious code as attachments (see instructions above).


Send report

This page outlines Automatic Systems’ coordinated disclosure policy, in accordance with our obligations under the European Cyber Resilience Act (Regulation (EU) 2024/2847).

You seem to be navigating from the United States or Canada.
Please continue your visit on our North American website.