Security Contact Page under the Cyber Resilience Act (CVD contact point)

Responsible handling of security vulnerabilities

SHF Communication Technologies AG (SHF) develops and distributes measurement instruments, modules and laboratory amplifiers that contain firmware and/or come with downloadable control software. The security of our products is a high priority for us. We take our obligations under the Cyber Resilience Act (Regulation (EU) 2024/2847) seriously and therefore provide a central contact point for reporting security vulnerabilities (Coordinated Vulnerability Disclosure, CVD).

If you have discovered a vulnerability in one of our products, in the associated firmware or in our control software, we ask you to report it to us through the channels listed below before making the information public.

 

Scope 

This reporting point covers:

  • all measurement instruments, modules, and laboratory amplifiers including their integrated firmware distributed by SHF Communication Technologies AG
  • the control software provided by us (both the download version and bundled versions)

 

How to report a vulnerability 

Please send your report to: 

  • Email:
  • Optional – encrypted communication
    PublicKey: SMIME
    Fingerprint: SHA-256 3F:1E:E7:1E:6A:1E:AD:30:D4:9F:94:7F:0A:6E:21:60:E1:39:C5:67:19:65:18:6D:13:46:AD:C3:4A:2F:74:8B

To help us process your report quickly, please include the following information:

  • Affected product/model and, if known, the firmware/software version
  • As precise a description of the vulnerability as possible
  • Steps to reproduce (proof of concept, if available)
  • Possible impact (e.g. unauthorised access, outage, manipulation of the control interface)
  • Your contact details for follow-up questions (optional)

 

What you can expect from us 

Step Timeframe
Acknowledgement of receipt of your report within 5 working days
Initial assessment / status update within 10 working days
Information on planned remediation and schedule on an ongoing basis, depending on severity
Publication of security advisories after remediation see section “Coordinated disclosure”

If the report concerns an actively exploited vulnerability or a severe security incident, we are additionally obliged to notify the competent CSIRT and ENISA within the statutory deadlines pursuant to Art. 14 CRA. This notification to the authorities does not replace our communication with you as the reporting party. 

 

Coordinated disclosure 

We ask you not to make details of a reported vulnerability public before:

  • we have confirmed the vulnerability and, where possible, provided an update or mitigation measure, or
  • a mutually agreed period (as a rule 90 days from receipt of the report) has elapsed.

Once a security update is available, we will – provided the risk situation permits – publish a security advisory containing information on the remediated vulnerability, the affected versions and recommended measures. 

 

Good faith / safe harbour 

We consider security research carried out in good faith and in accordance with this policy to be authorised. In particular, this means:

  • You test only on devices/systems that you own yourself or for which you have explicit permission.
  • You avoid disrupting the ongoing operations of third parties, causing data loss or breaching data protection.
  • You give us a reasonable period to remediate before publishing details (see above).

If you comply with these principles, we will not initiate legal action against you.

 

Support period 

For our products we provide security updates for a period of 5 years from the placing on the market of the respective device.

Last updated: September 2026. This page is reviewed and updated regularly.

Privacy Overview

Our website uses cookies. You can set your preferences below. More information in our Privacy Policy.

Strictly Necessary

We store a cookie to save your cookie preferences. This cannot be disabled as otherwise our website would not function properly (this Cookie-Banner would be displayed at every page view).

Statistics & Marketing

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages. Keeping these cookies enabled helps us to improve our website. Further, we use Google Ads with conversion tracking to tailor our advertising on Google search pages.

Convenience

This website uses Google-Maps to display our location and YouTube to show videos. Both are 3rd party services and may store cookies on your computer. By disabling you will not be able to watch these videos or display the map.