merrid controls
Your Automation Systems Integrator

Public channel for reporting vulnerabilities and incidents.

We care about the security of our digital products. Therefore, we enable vulnerability reporting and cooperate with reporters as part of the Coordinated Vulnerability Disclosure (CVD) process, in accordance with the requirements of Regulation (EU) 2024/2847 — the Cyber Resilience Act (CRA).

What matters can you contact us about?

Vulnerabilities

Reporting vulnerabilities affecting Merrid Controls products.

Security incidents

Information about security incidents related to Merrid Controls software.

Product security

Information about known vulnerabilities, available updates and risk mitigation measures.

How can you submit a report?

Reports can be submitted by email or via the contact form:

cybersecurity@merrid.com.pl

Vulnerability/Incident Reporting Form

Thank you for submitting your report. It will be analysed in terms of its impact on the cybersecurity of Merrid Controls’ Products with Digital Elements.
We were unable to submit your report. Please try again or contact us at cybersecurity@merrid.com.pl

* required fields
Please provide only the data necessary to carry out the cybersecurity analysis. We will acknowledge receipt of your report within two business days. Please do not publish any details before coordinated disclosure has been agreed. Reports may be submitted in Polish or English. Our contact details in machine-readable format are available in the security.txt file compliant with RFC 9116. We do not offer rewards for vulnerability reports.Information on the processing of personal data is available in our Privacy Policy.

What information should an email report contain?

Contact details enabling further communication — please provide only the data necessary to process the report;
The name of the product, system or component;
The software or firmware version;
A description of the identified vulnerability, actively exploited vulnerability or information security incident;
The method and conditions under which the issue was detected;
The potential impact on product security;
Information about actions taken to date.

What should not be reported?

This channel is intended exclusively for cybersecurity-related communications. Reports concerning ongoing technical support, failures, operational issues or other matters unrelated to cybersecurity should be submitted through the standard technical support channels.

How do we handle reports?

Each report received is analysed and assessed in terms of its impact on the cybersecurity of Products with Digital Elements.

Where justified, we take measures aimed at:
- removing or mitigating the effects of the vulnerability;
- preparing and providing a security update;
- developing risk mitigation measures;
- providing users with the necessary information and recommendations.

Detailed rules for receiving, analysing and disclosing vulnerability information are set out in the Coordinated Vulnerability Disclosure Policy.

Information on vulnerabilities and security updates

Information concerning confirmed vulnerabilities, available security updates and recommended actions is communicated directly to our customers.

Reports to the competent authorities

Independently of contacting Merrid Controls, pursuant to Article 15 of the CRA, any natural or legal person may voluntarily report a vulnerability, threat or incident related to a Product with Digital Elements to the competent CSIRT or to ENISA, in accordance with the applicable procedures.

fake video interview