Coordinated Vulnerability Disclosure (CVD) Policy
This policy describes how SHF Communication Technologies AG handles reported security vulnerabilities in its products and its infrastructure. It is addressed to security researchers, customers and any other person wishing to report a vulnerability (hereinafter the reporting party).
Scope
This policy applies to all measurement instruments, modules and laboratory amplifiers distributed by SHF Communication Technologies AG including their firmware, to the associated control software, and to the company’s IT infrastructure.
Contact and secure transmission
Please address your report to one of the following contacts:
- Product vulnerabilities (PSIRT):
PublicKey: SMIME
Fingerprint: SHA-256 13:EA:5A:D2:C1:63:CF:DF:B9:FF:02:A3:5C:68:66:A6:7C:15:00:6A:24:E4:C1:B4:CF:89:2A:3D:B6:A8:3F:1C - Infrastructure/IT vulnerabilities (CSIRT):
PublicKey: SMIME
Fingerprint: SHA-256 AB:61:F0:24:48:A0:D4:CC:DE:A9:B2:87:2E:8E:D9:F9:0E:92:23:93:B9:9C:52:0B:A6:AC:87:B4:2A:63:61:D4
We recommend transmitting confidential information by encrypted and digitally signed email. We accept at least email addresses and telephone numbers as contact channels.
Our commitments to the reporting party
We undertake to:
- treat every incoming report as confidential to the extent permitted by law (except for information required for public disclosure);
- not disclose the reporting party’s personal data to third parties without their explicit consent;
- respond within the deadlines set out below;
- not pursue a criminal complaint against the reporting party as long as this policy and its principles are complied with – this does not apply where criminal intent is recognisable;
- remain available as a point of contact for a trusted exchange throughout the entire CVD process;
- not require the reporting party to sign a non-disclosure agreement (NDA).
What we consider a valid vulnerability (vulnerability guideline)
We treat a report as a valid vulnerability if:
- it affects one of our products or our infrastructure;
- it relates, as far as possible, to information not yet publicly known;
- it is not solely the result of automated tools or scans without supporting documentation.
Guaranteed response times
We undertake to provide:
- an initial, non-automated response within 5 working days;
- detailed feedback following closer analysis within 10 working days.
The detailed feedback will contain at least either a confirmation or rejection of the reported vulnerability, meaningful follow-up questions to aid understanding, or an explanation of why the assessment is taking longer, together with a commitment to provide a further update within 10 working days.
Good communication
Respectful interaction between all parties is important to us; there is no room for discrimination, insults or similar behaviour. Status enquiries regarding a reported vulnerability are expressly welcome. Reports concerning vulnerabilities that have already been remediated are also received and reviewed. Please provide at least one valid contact channel (preferably an email address) for follow-up questions.
Handling of actively exploited vulnerabilities
If we become aware of an actively exploited vulnerability affecting one of our products or our infrastructure, we will notify the competent national CSIRT without undue delay and coordinate all new information, mitigation measures and schedules with it.
Disclosure of vulnerabilities
As a rule, we publicly disclose validated and verified vulnerabilities within 90 days. Where there is a legitimate reason, this period may be extended once by a further 90 days in close consultation with the competent national CSIRT; any extension beyond that is possible only through the national CSIRT upon our request. On request, disclosure takes place – in coordination with the national CSIRT or ENISA – at least via the European Vulnerability Database (EUVD) operated by ENISA.
End of the CVD process
We consider a CVD process to be complete when one of the following applies:
- the indications in the report prove to be unfounded;
- the vulnerability in a service has been remediated and publicly disclosed;
- the vulnerability has been remediated or mitigated by an appropriate patch and publicly disclosed;
- the reporting party fails to respond to technical or substantive queries for at least 30 days (in which case processing may be limited);
- the vulnerability has been publicly disclosed and – in consultation with the national CSIRT – it can no longer be assumed that it will be remediated or mitigated.
We inform the reporting party of the end of the CVD process without undue delay.
Last updated: September 2026. Responsible: SHF Communication Technologies AG (SHF).
