Reporting Security Vulnerabilities (Security Disclosure)
The security of our products is a high priority for us. If you have discovered a security vulnerability in one of our products or services, please inform us as soon as possible.
Contact
Email: security@as-drives.com
This mailbox is monitored by our Security Team and is set up to ensure a prompt response.
What information should your report include?
To enable us to assess the vulnerability quickly, please provide the following information:
– Affected product / affected version
– Description of the vulnerability
– Steps to reproduce the issue (Proof of Concept, if available)
– Potential impact from your perspective
– Your contact details for follow-up questions
What can you expect from us?
– Acknowledgement of receipt and initial assessment within 24 hours
– Detailed response within 72 hours
– Remediation status update no later than 14 days after an update or workaround has been made available
– Recognition as the finder/researcher (if desired) once the vulnerability has been resolved
Responsible Disclosure
We kindly ask you not to publicly disclose any identified vulnerabilities before a fix or workaround is available and not to access, modify, or delete any third-party data. Testing should be limited to what is necessary to demonstrate the vulnerability.
Legal Notice
We will not pursue legal action against individuals who report vulnerabilities under this policy in good faith and in accordance with the principles outlined above.
As a manufacturer of products with digital elements, we comply with the reporting obligations set out in Article 14 of EU Regulation 2024/2847 (Cyber Resilience Act).