Coordinated Vulnerability Disclosure (CVD) Policy
Last Updated: September 11, 2026
At QubicaAMF the security of our hardware and software products is a top priority. In compliance with the European Union’s Cyber Resilience Act (CRA), we are committed to ensuring a high level of cybersecurity for our users and we highly value the contributions of the security research community.
This policy outlines how to report potential security vulnerabilities found in our products and how we handle such reports.
1. Scope
This policy applies to all hardware and software products developed and commercialized by QubicaAMF as well as our connected web services and infrastructure.
2. How to Report a Vulnerability (Point of Contact)
If you believe you have discovered a security vulnerability in one of our products, we kindly ask you to report it to us promptly.
You can submit your report to our dedicated security team via:
Email: security@qubicaamf.com
What to include in your report: To help us understand and resolve the issue as quickly as possible, please provide:
The product name and the affected version (HW/SW).
A detailed description of the vulnerability.
The steps required to reproduce the issue (Proof of Concept, logs, screenshots, or videos).
The potential impact of the vulnerability.
3. Our Commitment
When we receive a vulnerability report, we commit to:
a) Acknowledge receipt of your report in a timely manner.
b) Assess and investigate the issue in a timely manner.
c) Keep you informed about the progress of the resolution.
d) Develop and deploy a security update (patch) to mitigate the vulnerability, in line with the requirements of the Cyber Resilience Act.
4. Guidelines for Researchers (Safe Harbor)
We appreciate the work of security researchers who act in good faith. We ask that you adhere to the following guidelines during your research:
Coordinated Disclosure: Please do not publicly disclose the details of the vulnerability before we have had a reasonable timeframe to analyze the issue and release a security update.
No Harm: Do not exploit the vulnerability to access other users' data, disrupt our services (e.g., DoS attacks), or destroy information.
Respect for Privacy: If you accidentally access personal or sensitive data during your research, stop your activities immediately and report it to us.
If you comply with these guidelines, QubicaAMF will not initiate any legal action against you in relation to your research.
5. Acknowledgments
We are grateful to those who help us improve the security of our products. If you wish, and subject to your consent, we will be happy to publicly acknowledge your contribution once the vulnerability has been resolved.
Note: This is our basic public reporting policy. Comprehensive internal procedures for vulnerability lifecycle management are maintained in compliance with the standards set forth by the Cyber Resilience Act.
