Coordinated Vulnerability Disclosure Policy

1. Purpose and Objective

iocto GmbH (“iocto”) develops and operates solutions in the fields of industrial measurement technology, automation, sensors, and software. The security of our products, systems, and services is of great importance to us.
Despite careful development, implementation, and testing, security vulnerabilities cannot be completely ruled out.
We therefore welcome responsible support of security researchers, customers, partners, and other individuals who discover security vulnerabilities in iocto products, systems, or services and report them to us confidentially.
This Coordinated Vulnerability Disclosure Policy (“Policy”) describes how security vulnerabilities should be reported to iocto and sets out the rules applicable to security research and the subsequent disclosure of information about vulnerabilities.

 

2. Scope

This Policy applies to external individuals and organizations that discover security vulnerabilities in iocto products, solutions, software, systems, or services and report them responsibly to iocto. The following are not covered by this Policy:

  • Customer and supplier systems
  • Third-party cloud services, unless iocto operates the respective service
  • Products that are no longer supported
  • Physical testing of production facilities
  • Systems for which iocto does not have the necessary authorization to conduct testing

 

3. Principles of Responsible Security Research

Security research should always be conducted with the objective of identifying security vulnerabilities and reporting them to iocto, while avoiding unnecessary impact on systems, data, iocto customers, or third parties.
Security researchers are therefore requested to:

  • Limit their investigations to the extent necessary and appropriate to identify and demonstrate a vulnerability
  • Respect the confidentiality, integrity, and availability of systems and data.
  • Avoid accessing personal, confidential, or otherwise sensitive information wherever possible.
  • Not access data that is not necessary to demonstrate vulnerability.
  • Not extend testing once sufficient evidence of the vulnerability has been obtained.
  • Report vulnerabilities to iocto confidentially and allow for coordinated disclosure.

When conducting security research on products, particularly measurement and automation systems, greatest care must be taken. Testing must not endanger individuals, equipment, production processes, or other physical systems.

 

4. Reporting Security Vulnerabilities

iocto provides two points of contact for reporting security vulnerabilities.
Sensitive information, in particular confidential or security-critical technical details, must be transmitted in encrypted form. If no suitable secure transmission method is available, iocto will agree with the reporter on a secure transmission method upon request.

4.1 Vulnerabilities in IT Systems

Vulnerabilities in iocto IT infrastructure and IT services can be reported to the CSIRT (Computer Security Incident Response Team):
csirt@iocto.com

This can include vulnerabilities in:

  • Websites and web applications
  • Servers and network services
  • Publicly reachable IT systems
  • Any other IT infrastructure operated by iocto

 

4.2 Vulnerabilities in Products

Vulnerabilities that affect a specific iocto product or a product-related solution or service can be reported to the PSIRT (Product Security Incident Response Team):
psirt@iocto.com

This can include vulnerabilities in:

  • Measurement, sensor, and automation products and systems
  • Software products, firmware, embedded software
  • Communication protocols implemented in products
  • Update and upgrade mechanisms
  • Any other component of an iocto product

 

5. Vulnerability Report Template

A well-structured report enables faster technical assessment. Wherever possible, a report should contain the following information:

  • Title or brief description of the vulnerability
  • Date (and, if applicable, time) of discovery or testing
  • Type of vulnerability
  • Affected IT system, service, product, or device, including version, model identifier, or configuration
  • Description of the vulnerability and how it was discovered
  • Potential impact
  • Preconditions for a successful exploit (e.g., remote, local, network, physical)
  • Steps to reproduce
  • Technical evidence (e.g., screenshots, logs)
  • Information about tests already performed
  • Suggested remediation or risk-mitigation measures
  • Name or alias of the author and contact details for follow-up questions

To protect our customers, iocto asks to keep any information about a possible vulnerability confidential until an appropriate coordination with iocto has taken place and not to disclose it publicly or to uninvolved third parties.

 

6. Prohibited Activities

The following activities are expressly not covered by this Policy:

  • Denial‑of‑Service or Distributed‑Denial‑of‑Service attacks (DoS and DDoS)
  • Social engineering, including phishing or similar deception attempts
  • Spam or mass registrations
  • Attacks on iocto employees, customers, or business partners
  • Installation of malicious software
  • Uploading potentially harmful files
  • Establishing persistent access
  • Intentional alteration or deletion of data
  • Unnecessary collection, storage, or disclosure of personal or confidential information
  • Exploiting a vulnerability beyond the extent required to demonstrate it
  • Physical attacks or unauthorized physical access
  • Tests that could endanger or impair individuals, facilities, production processes, or system availability
  • Any other actions that violate applicable law

This list is non-exhaustive. Additional activities may fall outside the scope of this Policy when they are incompatible with the Principles of Responsible Security Research (see Chapter 3).

 

7. Qualified Vulnerability Reports

The following types of security issues may be reported:

  • Remote Code Execution (RCE)
  • Command Injection
  • SQL Injection
  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)
  • Authentication, authorization, and access‑control flaws
  • Privilege Escalation
  • Unauthorized access to data or functions
  • Information or data leaks
  • Insecure APIs
  • Firmware or embedded‑software vulnerabilities
  • Vulnerabilities in update and upgrade mechanisms
  • Vulnerabilities in product‑related communication interfaces
  • Security‑relevant misconfigurations
  • Cryptographic weaknesses with concrete security impact
  • Vulnerabilities in third‑party components that are part of an iocto product or system and that have a concrete, security‑relevant impact on that product or system

 

8. Non-Qualified Reports

Not every security-related observation constitutes a security vulnerability. The following submissions are not considered security vulnerabilities under this Policy:

  • Pure recommendations for improving security
  • Missing or sub-optimal security headers without demonstrable security impact
  • Best-practice violations
  • Use of known vulnerable library or third-party component without proven exploitability
  • Results from automated scanners lacking further technical details
  • Information about publicly known vulnerabilities that does not indicate a relevant impact on an iocto product or system
  • Weak encryption or TLS configurations without a concrete security-impact

 

9. Handling of Reports

iocto welcomes security research conducted in accordance with the principles of this Policy.

When an individual or organization investigates a potential vulnerability in good faith and follows this Policy, iocto will treat the report as responsible security research within the limits of the law.

iocto will not initiate criminal proceedings against a reporter for actions that are deemed responsible and permissible security research under this Policy. The Policy does not grant a general right to access iocto or third-party systems, data, or facilities, and it does not protect any activity that is abusive, fraudulent, harmful, or otherwise illegal.

Upon receipt of a qualified report, iocto will review it, assess it at its discretion, and provide feedback to the reporter. In doing so, iocto reserves the right to decide, based on its own assessment, on appropriate remediation or mitigation measures. Information regarding the reported vulnerability and the reporter will be handled confidentially.

Effective Date: 14.09.2026
Version: 01.00