Security & Vulnerability Disclosure

We take the cybersecurity of our products and systems seriously. We appreciate responsible reports from customers, partners, security researchers, and other parties who identify potential security vulnerabilities in our products.

Reporting a vulnerability

If you believe you have discovered a security vulnerability in one of our products, machines, software applications, control systems, or connected services, please report it to: security@eqraft.com

Please include as much relevant information as possible, such as: the affected product or machine; model, serial number, and software or firmware version, where applicable; a description of the vulnerability; steps required to reproduce the issue; the potential security impact; relevant logs, screenshots, or other supporting information; and your contact details, unless you prefer not to provide them.

Please do not include personal data, confidential customer information, or other information that is not necessary for investigating the vulnerability.

Coordinated vulnerability disclosure

We follow a coordinated vulnerability disclosure process. This allows us to investigate reported vulnerabilities and, where necessary, develop and distribute appropriate mitigations or security updates before detailed information about a vulnerability is made public.

After receiving a vulnerability report, we will: acknowledge receipt of the report; assess and validate the reported vulnerability; investigate its potential impact on affected products; develop appropriate corrective or mitigating measures where necessary; and coordinate communication and disclosure where appropriate.

We ask reporters to allow us a reasonable period to investigate and address a reported vulnerability before publicly disclosing detailed information that could facilitate exploitation.

Responsible security research

When investigating a potential vulnerability, please act responsibly and avoid:

  • accessing, modifying, or deleting data that does not belong to you;

  • disrupting the operation of machines, production environments, or services;

  • compromising the safety of people, equipment, or production processes;

  • using a vulnerability beyond what is reasonably necessary to demonstrate its existence; or

  • disclosing vulnerability details before appropriate remediation and coordinated disclosure have taken place.

Security updates

Where a security vulnerability requires corrective action, we may provide security updates, mitigations, configuration guidance, or other security information to affected users.

Information about resolved vulnerabilities may be published where appropriate, including information identifying affected products, the potential impact and severity of the vulnerability, and recommended corrective measures.

Contact

For cybersecurity vulnerabilities relating to our products: security@eqraft.com

For general technical support or operational issues that are not cybersecurity-related, please use our regular service and support channels.