We care about the security of our digital products. Therefore, we enable vulnerability reporting and cooperate with reporters as part of the Coordinated Vulnerability Disclosure (CVD) process, in accordance with the requirements of Regulation (EU) 2024/2847 — the Cyber Resilience Act (CRA).
Reporting vulnerabilities affecting Merrid Controls products.
Information about security incidents related to Merrid Controls software.
Information about known vulnerabilities, available updates and risk mitigation measures.
Reports can be submitted by email or via the contact form:
* required fields
Please provide only the data necessary to carry out the cybersecurity analysis. We will acknowledge receipt of your report within two business days. Please do not publish any details before coordinated disclosure has been agreed. Reports may be submitted in Polish or English. Our contact details in machine-readable format are available in the security.txt file compliant with RFC 9116. We do not offer rewards for vulnerability reports.Information on the processing of personal data is available in our Privacy Policy.
This channel is intended exclusively for cybersecurity-related communications. Reports concerning ongoing technical support, failures, operational issues or other matters unrelated to cybersecurity should be submitted through the standard technical support channels.
Each report received is analysed and assessed in terms of its impact on the cybersecurity of Products with Digital Elements.
Where justified, we take measures aimed at:
- removing or mitigating the effects of the vulnerability;
- preparing and providing a security update;
- developing risk mitigation measures;
- providing users with the necessary information and recommendations.
Detailed rules for receiving, analysing and disclosing vulnerability information are set out in the Coordinated Vulnerability Disclosure Policy.
Information concerning confirmed vulnerabilities, available security updates and recommended actions is communicated directly to our customers.
Independently of contacting Merrid Controls, pursuant to Article 15 of the CRA, any natural or legal person may voluntarily report a vulnerability, threat or incident related to a Product with Digital Elements to the competent CSIRT or to ENISA, in accordance with the applicable procedures.
