Coordinated Vulnerability Disclosure (CVD) Policy

This policy describes how SHF Communication Technologies AG handles reported security vulnerabilities in its products and its infrastructure. It is addressed to security researchers, customers and any other person wishing to report a vulnerability (hereinafter the reporting party).

 

Scope

This policy applies to all measurement instruments, modules and laboratory amplifiers distributed by SHF Communication Technologies AG including their firmware, to the associated control software, and to the company’s IT infrastructure.

 

Contact and secure transmission

Please address your report to one of the following contacts:

  • Product vulnerabilities (PSIRT):
    PublicKey: SMIME
    Fingerprint: SHA-256 13:EA:5A:D2:C1:63:CF:DF:B9:FF:02:A3:5C:68:66:A6:7C:15:00:6A:24:E4:C1:B4:CF:89:2A:3D:B6:A8:3F:1C
  • Infrastructure/IT vulnerabilities (CSIRT):
    PublicKey: SMIME
    Fingerprint: SHA-256 AB:61:F0:24:48:A0:D4:CC:DE:A9:B2:87:2E:8E:D9:F9:0E:92:23:93:B9:9C:52:0B:A6:AC:87:B4:2A:63:61:D4

We recommend transmitting confidential information by encrypted and digitally signed email. We accept at least email addresses and telephone numbers as contact channels.

 

Our commitments to the reporting party

We undertake to:

  • treat every incoming report as confidential to the extent permitted by law (except for information required for public disclosure);
  • not disclose the reporting party’s personal data to third parties without their explicit consent;
  • respond within the deadlines set out below;
  • not pursue a criminal complaint against the reporting party as long as this policy and its principles are complied with – this does not apply where criminal intent is recognisable;
  • remain available as a point of contact for a trusted exchange throughout the entire CVD process;
  • not require the reporting party to sign a non-disclosure agreement (NDA).

 

What we consider a valid vulnerability (vulnerability guideline)

We treat a report as a valid vulnerability if:

  • it affects one of our products or our infrastructure;
  • it relates, as far as possible, to information not yet publicly known;
  • it is not solely the result of automated tools or scans without supporting documentation.

 

Guaranteed response times

We undertake to provide:

  • an initial, non-automated response within 5 working days;
  • detailed feedback following closer analysis within 10 working days.

The detailed feedback will contain at least either a confirmation or rejection of the reported vulnerability, meaningful follow-up questions to aid understanding, or an explanation of why the assessment is taking longer, together with a commitment to provide a further update within 10 working days.

 

Good communication

Respectful interaction between all parties is important to us; there is no room for discrimination, insults or similar behaviour. Status enquiries regarding a reported vulnerability are expressly welcome. Reports concerning vulnerabilities that have already been remediated are also received and reviewed. Please provide at least one valid contact channel (preferably an email address) for follow-up questions.

 

Handling of actively exploited vulnerabilities

If we become aware of an actively exploited vulnerability affecting one of our products or our infrastructure, we will notify the competent national CSIRT without undue delay and coordinate all new information, mitigation measures and schedules with it.

 

Disclosure of vulnerabilities

As a rule, we publicly disclose validated and verified vulnerabilities within 90 days. Where there is a legitimate reason, this period may be extended once by a further 90 days in close consultation with the competent national CSIRT; any extension beyond that is possible only through the national CSIRT upon our request. On request, disclosure takes place – in coordination with the national CSIRT or ENISA – at least via the European Vulnerability Database (EUVD) operated by ENISA.

 

End of the CVD process

We consider a CVD process to be complete when one of the following applies:

  • the indications in the report prove to be unfounded;
  • the vulnerability in a service has been remediated and publicly disclosed;
  • the vulnerability has been remediated or mitigated by an appropriate patch and publicly disclosed;
  • the reporting party fails to respond to technical or substantive queries for at least 30 days (in which case processing may be limited);
  • the vulnerability has been publicly disclosed and – in consultation with the national CSIRT – it can no longer be assumed that it will be remediated or mitigated.

We inform the reporting party of the end of the CVD process without undue delay.

Last updated: September 2026. Responsible: SHF Communication Technologies AG (SHF).

Privacy Overview

Our website uses cookies. You can set your preferences below. More information in our Privacy Policy.

Strictly Necessary

We store a cookie to save your cookie preferences. This cannot be disabled as otherwise our website would not function properly (this Cookie-Banner would be displayed at every page view).

Statistics & Marketing

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages. Keeping these cookies enabled helps us to improve our website. Further, we use Google Ads with conversion tracking to tailor our advertising on Google search pages.

Convenience

This website uses Google-Maps to display our location and YouTube to show videos. Both are 3rd party services and may store cookies on your computer. By disabling you will not be able to watch these videos or display the map.