Product cybersecurity

Safety integrated into the machine’s life cycle

Vulnerability management is part of our process for designing, developing, maintaining and updating products that incorporate digital elements.

  • CRA

    A process in line with Regulation (EU) 2024/2847.

  • Coordination team for reception, analysis and remediation.

Our commitment

A responsible relationship with those who help us improve safety

We want any researcher, client or partner to be able to report a finding clearly, securely and with a predictable response process.

How it works

A five-step report

Responsible disclosure

Before submitting the report

Avoid tests that could compromise people, production, third-party data or the availability of a machine.

Basic rules for research

  • Do not carry out denial-of-service attacks or destructive testing.
  • Do not modify or extract any data beyond what is strictly necessary to demonstrate the finding.
  • Do not attempt to pivot to other systems or networks.
  • If the test could affect axis movement, safety PLCs, emergency stops or other critical functions, stop it immediately.
  • Do not publish technical details until you have coordinated the disclosure with the PSIRT.

For particularly sensitive information, encrypted transmission using a public PGP key can be enabled.

Report a vulnerability

PSIRT Channel

Please complete each step. Required fields are checked before you can proceed.

  • Contact
  • Component
  • Vulnerability
  • Details and evidence
  • Confirmation

1 Contact

2 Component

3 Vulnerability

4 Details and evidence

5 Confirmation

Report summary

Contact A
Surname B
Email C
Phone -
Country
ID / Identity document
Organization
Associated machine number
Product or system
Component brand
Version
Title
Category
CVE/CWE reference
Description
Steps to reproduce
Impact
PoC
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Monitoring

What happens next?

FAQs

About CRA and vulnerabilities