Every security report is reviewed by our Product Security team and handled in accordance with the reporting obligations established by the Cyber Resilience Act (CRA).
Depending on the nature of the report, our process may include:
1. Review
We review the information provided and determine whether the report concerns a potential product security vulnerability or cyber incident.
2. Assessment
We assess the potential impact and severity of the reported issue.
3. Investigation
Where necessary, we investigate the issue and determine which products, versions or configurations may be affected.
4. Mitigation and remediation
Where appropriate, we identify and implement measures to address or reduce the identified risk.
5. Communication and Regulatory reporting
Where applicable, we provide feedback to the reporter and fulfil the relevant reporting obligations under the Cyber Resilience Act (CRA).
Our approach is focused on responsible handling of security issues and on continuously improving the security of our products.