Coordinated Vulnerability Disclosure CRA Compliant

Report a Security Vulnerability

We welcome reports of potential security vulnerabilities affecting APsystems EMEA products, software, services, or related digital elements. Reports submitted through our official channels are reviewed by our security team and entered into our internal tracking process.

What to Include

  • Product name and affected version, build number, model, or SKU
  • Platform, environment, or deployment context
  • Clear description of the potential vulnerability
  • Step-by-step instructions to reproduce the issue
  • Proof of concept or exploit details, if available
  • Observed or potential impact
  • Screenshots, logs, traces, or other supporting evidence
  • Your preferred contact information for follow-up
Acknowledgment and follow-up. Upon receipt of your report, APsystems EMEA will assign an internal tracking reference, acknowledge receipt within 24 hours, and enter the report into our internal tracking process. Our typical handling timeline is:
  • Within 24 hours — Acknowledgment and assignment of a tracking reference.
  • 3–5 business days — Initial triage to validate the report and assess severity.
  • 7 business days — Status update, including any request for additional information.
  • Remediation phase — Timeline depends on severity and complexity; high and critical issues are prioritized.
  • After resolution — Coordinated disclosure and publication of a security advisory, if applicable.

We will keep you informed of material changes to expected timelines and provide follow-up communication where appropriate.

Official Reporting Channels

Encrypting Sensitive Information

If your report contains especially sensitive technical details, you may encrypt your message or attachments using our PGP public key before sending it to security@apsystems.com.

Coordinated Disclosure

APsystems EMEA supports a coordinated disclosure approach. We ask reporters not to publicly disclose a vulnerability before remediation and coordinated publication have taken place, unless otherwise agreed in writing.

Disclosure timelines may vary depending on severity and exploitability, product impact and user risk, remediation availability, supply chain coordination needs, and other case-specific factors.

Anonymous Reporting

Anonymous reports may be accepted. Please note that anonymous reporting may limit our ability to request clarification, provide updates, or coordinate publication.

Legal Safe Harbor

We will not take legal action against researchers who follow responsible disclosure practices, including: making a good-faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services; and providing us reasonable time to remediate before public disclosure.

Help Center