Coordinated Vulnerability Disclosure Policy
This policy describes how security researchers, customers and partners can report potential vulnerabilities in ARCON products and related digital services.
| Manufacturer | ARCON GmbH, Wiesnerstr. 20, 4950 Altheim, Austria |
|---|---|
| German branch | ARCON GmbH Niederlassung Deutschland, Adalbert-Stifter-Strasse 2, 84085 Langquaid, Germany |
| Website | https://www.arconremote.com |
| Product security contact | psirt@arconremote.com |
| Incident contact | csirt@arconremote.com |
| Encryption key | https://www.arconremote.com/security/pgp-key.asc |
| Languages | English and German |
Scope
This policy applies to potential cybersecurity vulnerabilities in products, firmware, software, documentation, update mechanisms and product-related digital services provided by ARCON GmbH.
General IT incidents, phishing against ARCON employees, website abuse and operational security incidents can be reported to csirt@arconremote.com.
How to report a vulnerability
Please send vulnerability reports to psirt@arconremote.com. If the report contains sensitive technical details, exploit code or customer-specific information, please encrypt the message with the published OpenPGP key.
Please include, where available:
affected product, model, hardware revision, firmware/software version and configuration;
a clear description of the vulnerability and potential impact;
steps to reproduce the issue, proof-of-concept information or logs;
whether the vulnerability is known to be actively exploited;
your contact details and preferred communication channel;
any planned disclosure date or coordination requirements.
Responsible research rules
ARCON asks researchers to act responsibly and to avoid harm. In particular:
do not access, modify, delete or exfiltrate data that does not belong to you;
do not disrupt availability of ARCON systems, customer systems or products in operation;
do not use social engineering, physical attacks, malware or denial-of-service techniques;
do not publicly disclose the vulnerability before ARCON has had a reasonable opportunity to assess and address it;
report the vulnerability promptly and keep communication confidential during coordination.
Our response
ARCON will acknowledge receipt of vulnerability reports within seven calendar days where sufficient contact information is provided. ARCON will assess the report, may request additional information, and will coordinate remediation and disclosure based on severity, product risk and customer impact.
As a general target, ARCON provides status updates at least every 30 days for confirmed vulnerabilities until remediation or coordinated closure. Exact remediation timelines depend on product type, severity, safety impact, customer deployment constraints and required validation.
Coordinated disclosure
ARCON supports coordinated vulnerability disclosure. Public disclosure should be coordinated with ARCON so that affected users can be informed and corrective measures can be prepared. A typical coordination period is 90 days after confirmation, unless a different timeline is agreed or legal, safety or exploitation circumstances require a different approach.
Regulatory reporting
Where required by applicable law, ARCON will report actively exploited vulnerabilities or severe incidents affecting products with digital elements through the competent reporting channels, including the ENISA Single Reporting Platform once applicable and available.
No bug bounty
ARCON does not currently operate a public bug bounty programme. Submitting a report does not create an entitlement to payment, reward or employment.
Safe harbor statement
ARCON does not intend to take legal action against researchers who make a good-faith effort to comply with this policy, avoid harm, respect privacy and confidentiality, and stop testing immediately if they encounter sensitive data or operational impact. This statement does not permit unlawful activity and does not bind third parties.
Review
This policy and the related security.txt file are reviewed at least quarterly and updated when contacts, reporting channels or legal requirements change.
Last reviewed: 2026-06-11
Canonical security.txt: https://www.arconremote.com/.well-known/security.txt