Regulation (EU) 2024/2847

Cyber Resilience Act (CRA)

Product security and reporting of vulnerabilities

Our commitment to product security

Water-i.d. GmbH attaches great importance to the cybersecurity of its products and digital solutions. In line with the requirements of the European Cyber Resilience Act (CRA), we take every report of a potential security vulnerability seriously and handle it confidentially.

This applies in particular to our products with digital elements, such as photometers with firmware and wireless interfaces (e.g. Bluetooth, WiFi), our apps, our software and our cloud services.

What your report should contain

To help us analyse your report quickly, please provide as much of the following information as possible:

  • Product name and version (hardware, firmware, app or software version)
  • Description of the vulnerability
  • Technical details and steps to reproduce it
  • Your assessment of the possible impact
  • Date on which the vulnerability was discovered
  • Known workarounds or countermeasures, if any
  • Your contact details for any follow-up questions

How we handle your report

  1. Acknowledgement We confirm receipt of your report as soon as possible.
  2. Analysis Our team verifies and assesses the reported vulnerability and may contact you for further details.
  3. Remediation We develop and provide suitable measures, e.g. security updates or recommendations for action.
  4. Information We inform affected users and, where required by law, the competent authorities. Actively exploited vulnerabilities and severe security incidents are reported via the ENISA Single Reporting Platform.

Coordinated vulnerability disclosure

We ask you to follow these principles:

  • Please do not publish the vulnerability before we have had sufficient opportunity to analyse it and implement appropriate measures.
  • Do not access, modify or delete data of third parties, and only carry out tests to the extent necessary to demonstrate the vulnerability.
  • Refrain from attacks that affect the availability of our services (e.g. denial of service) as well as from social engineering or physical attacks.

We treat your report confidentially and will not share your personal data with third parties without your consent.

Vulnerability reporting form

Fields marked with * are required.

Thank you! Your report has been sent to our security team.

Your contact details

Affected product

Start typing to choose one of our products. If your product is not listed, simply enter its name yourself (e.g. app, software or cloud service). This product is not in our list. Your entry will be submitted as typed.

Vulnerability

Optional, e.g. screenshots or log files. Up to 3 files, max. 5 MB each and 10 MB in total. Allowed formats: PDF, PNG, JPG, JPEG, GIF, WEBP, TXT, LOG, CSV, JSON, XML, ZIP.

Please do not send passwords, personal data of third parties or exploit code that could cause damage. If needed, we will agree on a secure channel with you.