Skip to main content

Security & Vulnerability Disclosure

optiMEAS develops intelligent measurement and IoT systems for industrial use. Keeping these products secure is an ongoing task, and we work openly with the people who help us find and fix vulnerabilities.

This page explains how to report a possible vulnerability in an optiMEAS product or service, and what you can expect from us in return. It implements the requirement of the EU Cyber Resilience Act (Regulation (EU) 2024/2847, Annex I, Part II, No. 5) to provide and apply a coordinated vulnerability disclosure policy.

Report a vulnerability

Email security@optimeas.de — a PGP key for encrypted reports is available on request. Please report privately and do not disclose the issue publicly until we have agreed on a coordinated disclosure.

Scope

This policy applies to optiMEAS products with digital elements and their related services, in particular:

  • measurement and data-acquisition systems (hardware including firmware)
  • optiMEAS software and applications for configuration, visualisation, and data analysis
  • cloud and portal services as well as update and licensing infrastructure
  • our websites and customer portals

Out of scope are third-party systems and services we do not operate ourselves, and products that have reached the end of their support period. Please report findings anyway — where possible we forward them to the responsible party.

How to report

Send your report to security@optimeas.de. The following details help us respond quickly:

  • the affected product, version or firmware, and environment
  • a clear description of the vulnerability and its potential impact
  • steps to reproduce the issue (proof of concept, logs, or screenshots welcome)
  • how we can reach you, and whether you would like to be credited

Reports in English or German are both fine. Incomplete reports are still welcome — we will follow up if we need more detail.

What you can expect from us

StepOur commitment
Acknowledgementwithin 3 business days of your report
Initial assessmentwithin 10 business days, including our classification
Remediationaccording to severity, without undue delay, with progress updates
Coordinated disclosuretiming and content agreed together once a fix is available

For complex or critical cases we will tell you transparently if we need more time.

What we rely on together

We consider security research carried out in good faith and in line with this policy to be a valued contribution, not unauthorised access. If you follow the principles below, we will not pursue or recommend legal action in connection with your research:

  • access only the data necessary to demonstrate the vulnerability, and do not modify, delete, or disclose data belonging to others
  • do not degrade the operation or availability of our systems for other users (no denial of service, no bulk or spam testing)
  • keep the vulnerability and any information obtained confidential until we have agreed on disclosure
  • give us a reasonable time to fix the issue — normally 90 days — before publishing details

This assurance applies only to the extent permitted by law, does not grant permission for testing beyond what is needed to report an issue, and does not protect against third-party claims.

We handle vulnerabilities on a coordinated-disclosure basis: publication happens once a corrective measure is available and affected customers can be protected. Where appropriate we request a CVE identifier and, with your consent, credit your contribution.

Independently of this, we meet our legal obligations under the Cyber Resilience Act. Actively exploited vulnerabilities and severe security incidents are reported within the statutory deadlines to the competent CSIRT and ENISA via the designated European reporting platform. Our process follows the established standards ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability handling).

Recognition

We value the work of security researchers and will credit you as the finder of a confirmed vulnerability if you wish. We do not currently operate a paid bug bounty programme.


Security contact: security@optimeas.de · Version 1.0 (July 2026)