Vulnerability or Security Incident

PRODUCT SECURITY POLICY — AUTOMATIC SYSTEMS

Report a vulnerability or security incident

Automatic Systems takes the security of its products and systems seriously. If you are a customer, integrator, or security researcher and believe you have identified a vulnerability or incident affecting one of our products, please let us know.

PSIRT Contact Point

PGP Key:
[fingerprint / link to public key][cite: 2]
Acknowledgment of receipt:
within 1 business day[cite: 2]
What we ask of you[cite: 2]

So that we can process your report quickly and efficiently:

  • Describe the vulnerability as accurately as possible: product, version, affected configuration, and the steps to reproduce it.
  • Allow us a reasonable time to analyze and fix the problem before any public disclosure.
  • Act in good faith: do not access data that does not belong to you, do not interrupt our services, and limit your tests to what is strictly necessary to demonstrate the vulnerability.
  • Do not test on production installations at our customers’ sites without their explicit consent.

Reports made under these conditions will not be subject to any legal action on our part.

Our commitment & Processing times

Once your report is received, here is the process we follow:

Within 1 business day
Acknowledgment of receipt with a point of contact and a tracking number.
Within 24 hours, 24/7
Initial severity triage, in particular to determine if the report corresponds to an active exploitation or a severe incident.
Within 15 business days
Comprehensive evaluation: detailed confirmation of the vulnerability, final severity level, and affected products/versions.
Depending on severity
Development and deployment of a patch or mitigation measure, including notification to affected customers.
After correction[cite: 2]
Publication of a security advisory summarizing the vulnerability and the patch, and thanking the reporter.
Actively exploited vulnerability or ongoing incident?
Explicitly indicate this in the subject of your report and contact your usual support or sales contact.
Scope of application
Status Scope description
In scope Products, embedded software, applications, and web interfaces of Automatic Systems currently marketed or under support period.
Out of scope Third-party infrastructure or services, end-of-support products, social engineering, denial of service attacks.

Submit a report

To ensure the security and confidentiality of communications, reports are made directly by email. The button below will open your email client with a pre-filled template.

Information you will be asked for in the email:

  • Your name and contact email
  • The affected product / system and its version
  • The estimated severity (Critical, High, Medium, Low)
  • The detailed description and reproduction steps
  • Confirmation of any active exploitation

Attachments: Please attach your proofs of concept (PoC, screenshots, logs) directly in the email that will open.


Send a report email

This page describes the coordinated disclosure policy of Automatic Systems, in accordance with the obligations under the European Cyber Resilience Act (Regulation (EU) 2024/2847).

You seem to be navigating from the United States or Canada.
Please continue your visit on our North American website.