Did You Find a Vulnerability?
Our goal is to handle potential vulnerabilities in a quick and transparent manner. You can report an issue by contacting us via our reporting email at security@cs‑instruments.com or using the contact form on this page. We recommend using the contact form, as it guides you through all necessary information in a structured manner. Alternatively, feel free send your details formless to our reporting email.
Please note that we do not consider (D)DoS attacks and social engineering attacks as report‑worthy vulnerabilities under Coordinated Vulnerability Disclosure (CVD).
What Information Do We Need
To efficiently review your report and to avoid follow‑up questions, please provide at least the following information:
- Description of the Vulnerability: The more details you can give us about the vulnerability, the faster we can identify its exact cause.
- Affected Product and Version: This helps us issue warnings to our users if necessary and fulfill our reporting obligations promptly.
- Steps to Reproduce: These Steps allow us to independently verify and prioritize the vulnerability.
- Your Contact Information: For any follow‑up questions and status updates (Email, possibly phone).
You Are Safe With Us
We provide you with safe harbor protection as long as your report is made in good faith without unauthorized access or malicious intent. We commit not to initiate legal action against you as long as you adhere to the above conditions.
What Happens After Your Report
After receiving your report, you will receive a timely acknowledgment by email. The responsible developers will then review your report. They analyze the reported vulnerability, assess its impact, and prioritize it according to its criticality. If there are any questions or additional information is needed, we will contact you directly. We will keep you informed about our progress throughout the entire handling process. After successful validation, a fix is developed, and will be rolled out no later than 90 days after receiving your report.
Are you planning to publish your finding yourself? Please feel free to reach out to us to coordinate the publication. In accordance with regulatory requirements, particularly under the Cyber Resilience Act (CRA), we will report relevant security incidents and vulnerabilities to the appropriate authorities.
To help us review your report efficiently and avoid the need for follow-up questions, please fill out the following fields: