Product security

Vulnerability Disclosure Policy

How to report a potential vulnerability in a Servomex product, and how we coordinate investigation, remediation and responsible disclosure.

Introduction

Servomex is committed to providing secure products, software and services. We welcome good-faith reports from security researchers, customers, partners and other members of the security community that help us identify and remediate potential vulnerabilities in Servomex products and product-related digital services.

Servomex operates a Coordinated Vulnerability Disclosure (CVD) process under which reported vulnerabilities are assessed, validated, prioritised, remediated or mitigated, and disclosed in a coordinated manner. This Vulnerability Disclosure Policy (VDP) explains what is in scope, how to report a vulnerability, what we ask of researchers, what researchers can expect from us, and how coordinated public disclosure should be handled.

Authorisation and safe harbour

If you make a good-faith effort to comply with this policy, keep your testing within the stated scope, and avoid harm to people, customers, systems and data, Servomex will treat your research as authorised. Servomex will not pursue civil action or initiate a complaint to law enforcement against individuals acting in good faith and in compliance with this policy, and will not pursue anti-circumvention claims in relation to such research. If a third party initiates legal action against you for activities conducted in accordance with this policy, Servomex may make this authorisation known where appropriate.

This authorisation does not apply to activity that is unlawful, harmful, destructive, disruptive, privacy-invasive, outside the stated scope, or otherwise inconsistent with this policy. It does not authorise access to, or testing of, systems or data owned by customers, suppliers or other third parties.

Scope

This policy applies to potential security vulnerabilities in Servomex products with digital elements, including embedded firmware, Servomex-supplied software and product-related digital services produced or distributed by Servomex. Servomex welcomes good-faith reports concerning both current and legacy products.

The following are out of scope: corporate IT systems; general Servomex websites not used for product support or product security; supplier, customer and distributor systems; physical premises; employee accounts; and systems not owned or operated by Servomex. Third-party systems and services are out of scope unless they are expressly provided by Servomex as part of a Servomex product-related digital service. Vulnerabilities in other third-party products or services should normally be reported to the relevant vendor or service provider.

You may test only a product or device that you own, or for which you have the owner’s explicit permission to conduct security testing. This policy does not authorise testing against operational customer environments, production systems, third-party systems or services, or any system where testing could create a safety, security, privacy or availability risk.

Receipt, acknowledgement, triage or validation of a report does not constitute a commitment to provide remediation, updates, continued maintenance or any particular support period. Servomex will determine the appropriate response case by case, taking account of factors including severity, exploitability, safety and customer impact, affected products, technical feasibility, applicable legal obligations, and the availability of remediation or mitigation.

If you are unsure whether a product, service, system or proposed testing activity is in scope, contact Servomex before testing.

Research guidelines

  • Notify Servomex as soon as possible after discovering a real or potential security issue.
  • Use only the minimum testing needed to confirm the presence of a vulnerability.
  • Avoid privacy violations, degradation of service, disruption to production systems, safety impact, or destruction, alteration or exfiltration of data.
  • Stop testing and notify Servomex immediately if you encounter personal data, customer data, proprietary information, trade secrets, credentials, cryptographic keys or other sensitive information.
  • Do not establish persistence, pivot to other systems, use compromised access beyond proof of vulnerability, or attempt lateral movement.
  • Do not submit high-volume, automated or low-quality reports.
  • Keep vulnerability details confidential while coordinated disclosure is in progress and contact Servomex before any third-party or public disclosure.

Testing not authorised under this policy

  • Network denial-of-service, distributed denial-of-service, stress, load or destructive testing.
  • Physical testing, facility access attempts, tailgating, device theft, tampering with customer equipment, or testing that could create safety risk.
  • Social engineering, phishing, vishing, smishing, pretexting or attempts to access employee accounts.
  • Malware deployment, persistence, ransomware, cryptomining, botnet activity or credential harvesting.
  • Accessing, modifying, deleting, exfiltrating or publicly disclosing data beyond the minimum necessary to demonstrate a vulnerability.

Reporting a vulnerability

Please send vulnerability reports using one of the following channels:

Fingerprint: 08C1 2442 3D21 DCF0 BCAE BE23 5892 6230 E9F4 A3DE
Valid until: 27 August 2029 at 12:00 UTC

Information on reporting vulnerabilities is also published through the Servomex security.txt file. Please do not send sensitive vulnerability details through ordinary email; if encryption is unavailable, use ordinary email only to establish an appropriate secure channel.

Please do not use these channels for non-product-security enquiries, sales enquiries, support tickets that do not involve a security issue, or generic vulnerability-scanning reports with no product-specific evidence.

What to include in a report

To help us validate, triage and prioritise a submission, we recommend that reports include:

  • Affected Servomex product, software, firmware, service, version, configuration, interface or component.
  • A description of the vulnerability and its potential security impact.
  • Steps to reproduce, proof-of-concept details, screenshots, logs or other evidence where safe to share.
  • Whether the issue is remotely, locally or physically reachable, or requires credentials or special configuration.
  • Whether exploitation has been observed or is publicly known.
  • Suggested mitigation or remediation, if known.
  • Your preferred contact details and whether you want to be credited in any public advisory.

What you can expect from Servomex

  • If you provide contact details, Servomex will normally acknowledge receipt within five business days. Acknowledgement does not mean that the report has been validated or accepted as a vulnerability.
  • Following acknowledgement, Servomex will begin initial triage to assess whether the report is sufficiently complete, relates to an in-scope Servomex product or service, and identifies a potential security impact. Servomex may request clarification or additional evidence during triage.
  • Validation requires Servomex to reproduce or otherwise confirm the reported vulnerability. The time needed will vary according to the report’s completeness, technical complexity, affected product, safety implications and need for supplier or customer coordination; acknowledgement or triage does not constitute validation.
  • Vulnerabilities will be prioritised according to their severity, exploitability, affected products, technical feasibility, availability of mitigation and potential customer, safety and security impact.
  • Servomex will aim to keep you informed of material status changes where this is practical, proportionate and legally permissible.
  • Where appropriate, Servomex will publish or update a security advisory describing affected products and versions, severity, available remediation or mitigation, and current status.
  • Servomex may coordinate with suppliers, customers, regulators, CSIRTs, Spectris Group or other affected parties where required by law, contract, safety, security or coordinated-disclosure considerations.

Reports may be submitted anonymously. Anonymous reports will be reviewed to the extent possible; however, Servomex may be unable to validate or remediate a vulnerability where sufficient technical information is not provided, and cannot acknowledge receipt, request clarification or coordinate disclosure without a contact route.

Servomex does not currently offer a bug bounty, finder fee or other reward unless a separate written programme states otherwise. Servomex may, with your express consent, publicly recognise you or your organisation for a valid report after remediation or coordinated disclosure. Recognition is optional, is not compensation, creates no entitlement to any benefit, and remains subject to applicable sanctions, export-control, anti-bribery, privacy, confidentiality and other legal requirements.

Coordinated disclosure

We request a minimum coordinated-disclosure period of 90 calendar days from Servomex validation of the vulnerability. Where remediation requires additional time, or safety, regulatory reporting, supplier coordination, customer deployment or patch availability considerations require a different timeline, Servomex and the reporter may agree an alternative disclosure schedule. Servomex asks researchers not to disclose vulnerability details publicly or to third parties before the agreed disclosure date, except where disclosure is required by law.

Where public communication is appropriate, validated vulnerabilities may result in a new or updated Servomex Security Advisory. The timing and content of an advisory will be coordinated with remediation or mitigation availability, affected parties, legal and regulatory requirements, and the agreed disclosure schedule.

Data handling and privacy

Information submitted under this policy will be used for defensive purposes, including investigation, validation, remediation, mitigation, risk assessment, regulatory reporting where required, and communication with affected parties. Servomex will handle submitted reports and related personal data in accordance with applicable confidentiality, privacy and data-protection requirements. Servomex will not share a researcher’s name or contact information externally without permission unless required by law or necessary to protect safety or security.

Changes to or termination of this policy

Servomex may update or terminate this policy from time to time. Any change or termination will apply prospectively only and will not affect a report already submitted in good faith under the version of the policy in effect at the time of submission. The version published on the Servomex website is the current public version.

Questions

Questions about this policy, including questions about scope, may be sent to psirt@servomex.com. We also welcome suggestions for improving this policy.


© Copyright 2026 - Servomex is a Spectris company.
Click here to download your selected documents