Skip to main content Skip to page footer

Product Cybersecurity

Report Security Gaps and Incidents Safely & Systematically

Sesotec designs systems for critical industrial processes. We prioritize the safety of these systems just as much as their reliability. This page explains how customers and security researchers can report vulnerabilities and security incidents to us.

Report Form        Vulnerability Disclosure Policy

Our Principles

Sesotec systems are integral to our clients' critical production and recycling processes. That's why we see cybersecurity not as an afterthought, but as a core element of our product development, operation, and support. Our commitment includes:

  • Security-by-Design in development and product maintenance
  • A structured, traceable approach to reported vulnerabilities
  • Transparent, fair communication with reporters
  • Compliance with our regulatory obligations, including the Cyber Resilience Act (CRA)
  • Mandatory reporting of actively exploited vulnerabilities & critical incidents to authorities under Art. 14 CRA
  • This page supports our internal processes for handling such reports
  • It does not replace legal advice or establish contractual commitments

What to Report

The scope of this Security Policy – and what is explicitly excluded.

ON TARGET

Security Topics 
  • Vulnerabilities in Sesotec products, control software, and firmware 
  • Vulnerabilities in Sesotec web applications and cloud services 
  • Exploited vulnerabilities and security incidents in field devices 
  • Insights from responsible security research (Coordinated Disclosure)
OUT OF SCOPE
Not Part of This Page 
  • General product, order, or service inquiries without a security focus → please continue to contact service@sesotec.com
  • Social engineering or phishing attempts targeting employees
  • Denial-of-Service tests or any testing on live customer systems without their explicit consent
  • Vulnerabilities in third-party software or components not originating from Sesotec

Vulnerability Disclosure Policy

How we handle reports – and what we expect from reporters

Welcome

We promptly acknowledge receipt of your report.

Testing

Our team assesses the relevance and severity of the report.

Processing

We collaborate with you to establish a realistic timeline for resolution

Close

We will keep you updated on the outcome and actions taken.

What We Expect from You 
  • Act solely to identify vulnerabilities 
  • Allow us sufficient time to address issues before public disclosure 
  • Report findings using the form below instead of public channels 
  • Keep obtained information confidential
What to Avoid 
  • Do not exploit the vulnerability beyond demonstration (no data access, alteration, or leakage) 
  • Do not access third-party systems or data 
  • Do not disclose or share with third parties without our consent 
  • Do not conduct tests that could compromise the operation or security of customer facilities

By adhering to these principles, we approach your report with cooperation and a focus on solutions. This page does not provide any additional legal assurance.

Report Vulnerability or Incident

Submit structured reports via our web form. Currently, this is the only available method – there is no dedicated security email address.

Privacy information according to Art. 13 and 14 GDPR: Details about data processing related to your contact request can be found in our Privacy Policy.

No security concerns?

For general inquiries about products, spare parts, or services not related to safety, please continue to contact us as usual at service@sesotec.com or via our Service Hotline.