Cyber Resilience Act (CRA)
Product security and reporting of vulnerabilities
Our commitment to product security
Water-i.d. GmbH attaches great importance to the cybersecurity of its products and digital solutions. In line with the requirements of the European Cyber Resilience Act (CRA), we take every report of a potential security vulnerability seriously and handle it confidentially.
This applies in particular to our products with digital elements, such as photometers with firmware and wireless interfaces (e.g. Bluetooth, WiFi), our apps, our software and our cloud services.
What your report should contain
To help us analyse your report quickly, please provide as much of the following information as possible:
- Product name and version (hardware, firmware, app or software version)
- Description of the vulnerability
- Technical details and steps to reproduce it
- Your assessment of the possible impact
- Date on which the vulnerability was discovered
- Known workarounds or countermeasures, if any
- Your contact details for any follow-up questions
How we handle your report
- Acknowledgement We confirm receipt of your report as soon as possible.
- Analysis Our team verifies and assesses the reported vulnerability and may contact you for further details.
- Remediation We develop and provide suitable measures, e.g. security updates or recommendations for action.
- Information We inform affected users and, where required by law, the competent authorities. Actively exploited vulnerabilities and severe security incidents are reported via the ENISA Single Reporting Platform.
Coordinated vulnerability disclosure
We ask you to follow these principles:
- Please do not publish the vulnerability before we have had sufficient opportunity to analyse it and implement appropriate measures.
- Do not access, modify or delete data of third parties, and only carry out tests to the extent necessary to demonstrate the vulnerability.
- Refrain from attacks that affect the availability of our services (e.g. denial of service) as well as from social engineering or physical attacks.
We treat your report confidentially and will not share your personal data with third parties without your consent.
Vulnerability reporting form
Fields marked with * are required.