Security & Vulnerability Disclosure
optiMEAS develops intelligent measurement and IoT systems for industrial use. Keeping these products secure is an ongoing task, and we work openly with the people who help us find and fix vulnerabilities.
This page explains how to report a possible vulnerability in an optiMEAS product or service, and what you can expect from us in return. It implements the requirement of the EU Cyber Resilience Act (Regulation (EU) 2024/2847, Annex I, Part II, No. 5) to provide and apply a coordinated vulnerability disclosure policy.
Email security@optimeas.de — a PGP key for encrypted reports is available on request. Please report privately and do not disclose the issue publicly until we have agreed on a coordinated disclosure.
Scope
This policy applies to optiMEAS products with digital elements and their related services, in particular:
- measurement and data-acquisition systems (hardware including firmware)
- optiMEAS software and applications for configuration, visualisation, and data analysis
- cloud and portal services as well as update and licensing infrastructure
- our websites and customer portals
Out of scope are third-party systems and services we do not operate ourselves, and products that have reached the end of their support period. Please report findings anyway — where possible we forward them to the responsible party.
How to report
Send your report to security@optimeas.de. The following details help us respond quickly:
- the affected product, version or firmware, and environment
- a clear description of the vulnerability and its potential impact
- steps to reproduce the issue (proof of concept, logs, or screenshots welcome)
- how we can reach you, and whether you would like to be credited
Reports in English or German are both fine. Incomplete reports are still welcome — we will follow up if we need more detail.
What you can expect from us
| Step | Our commitment |
|---|---|
| Acknowledgement | within 3 business days of your report |
| Initial assessment | within 10 business days, including our classification |
| Remediation | according to severity, without undue delay, with progress updates |
| Coordinated disclosure | timing and content agreed together once a fix is available |
For complex or critical cases we will tell you transparently if we need more time.
What we rely on together
We consider security research carried out in good faith and in line with this policy to be a valued contribution, not unauthorised access. If you follow the principles below, we will not pursue or recommend legal action in connection with your research:
- access only the data necessary to demonstrate the vulnerability, and do not modify, delete, or disclose data belonging to others
- do not degrade the operation or availability of our systems for other users (no denial of service, no bulk or spam testing)
- keep the vulnerability and any information obtained confidential until we have agreed on disclosure
- give us a reasonable time to fix the issue — normally 90 days — before publishing details
This assurance applies only to the extent permitted by law, does not grant permission for testing beyond what is needed to report an issue, and does not protect against third-party claims.
Coordinated disclosure and legal reporting
We handle vulnerabilities on a coordinated-disclosure basis: publication happens once a corrective measure is available and affected customers can be protected. Where appropriate we request a CVE identifier and, with your consent, credit your contribution.
Independently of this, we meet our legal obligations under the Cyber Resilience Act. Actively exploited vulnerabilities and severe security incidents are reported within the statutory deadlines to the competent CSIRT and ENISA via the designated European reporting platform. Our process follows the established standards ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability handling).
Recognition
We value the work of security researchers and will credit you as the finder of a confirmed vulnerability if you wish. We do not currently operate a paid bug bounty programme.
Security contact: security@optimeas.de · Version 1.0 (July 2026)