1. Purpose and scope
The purpose of the CVD Policy is to enable security researchers, customers, partners and other individuals to report potential vulnerabilities in a responsible and secure manner, allowing them to be remediated in a coordinated way before technical information is disclosed.The Policy applies to Products with Digital Elements manufactured or maintained by Merrid Controls, their supported versions, online services and infrastructure identified as being within scope.A detailed list of supported products and versions is available at:
https://merrid.com.pl/systemy
Systems, services and components of third parties over which Merrid Controls has no control are out of scope, unless expressly indicated otherwise.
Reports concerning privacy, fraud, abuse or general technical support should be submitted, as appropriate, to:
merrid@merrid.com.pl.
2. Contact and secure reportingThe preferred reporting channel is the form available at:
https://merrid.com.pl/cybersecurity or by email:
cybersecurity@merrid.com.pl
Reports may be submitted in Polish or English. To protect confidential information, please use the PGP key available at :
https://merrid.com.pl/.well-known/pgp-key.txt.
Key fingerprint:
Reporting portal: https://merrid.com.pl/cybersecurity
security.txt file: https://merrid.com.pl/.well-known/security.txt
Reports should not contain personal data, credentials or customer data unless this is necessary. In such cases, a secure method of transferring the data should be agreed in advance.
3. Information to be included in a reportTo facilitate an efficient assessment, a report should contain as much complete information as possible.
The absence of some information is not grounds for rejecting a report, provided that the issue can be clarified during further communication.
-The name of the product, component or service, including its version, environment and configuration.
-A description of the vulnerability and its potential impact on the confidentiality, integrity or availability of the product, or on user security.
-Reproduction steps, proof of concept and required prerequisites.
-Information about any known or suspected active exploitation of the vulnerability.
-The reporter’s contact details and their preference regarding attribution in a security advisory.
4. Rules for reportersMerrid Controls permits good-faith security research solely to the extent necessary to identify and confirm a vulnerability.
Reporters should limit the impact of their activities, protect any information obtained and refrain from publicly disclosing vulnerabilities before the agreed disclosure date.
-Services must not be disrupted or degraded, and DoS/DDoS attacks must not be conducted.
-Data belonging to other individuals must not be accessed, modified, deleted or published beyond the minimum necessary to confirm the vulnerability.
-Social engineering, phishing, physical access attempts, malware or attacks against employees, customers or suppliers must not be used.
-Vulnerabilities must not be used to obtain financial gain, conduct extortion or carry out further unauthorised activities.
-If access to data or accounts is obtained accidentally, the test must be stopped immediately. The data must not be copied, and the incident must be described in the report.
5. Safe harbour
If a reporter acts in good faith, in accordance with this Policy and applicable law, Merrid Controls will not initiate civil or criminal proceedings against the reporter solely on the basis of security research conducted in accordance with these rules. This does not limit Merrid Controls’ obligations under applicable law or the rights of third parties. If there is any doubt regarding the permissibility of planned activities, the reporter should contact the security team before commencing them.
6. Report handling Merrid Controls registers every report, assigns it an identifier and conducts a process involving acknowledgement of receipt, validation, triage, risk assessment, a decision on remediation or risk mitigation, testing and communication with the reporter.
Reports are treated as confidential, subject to legal and regulatory obligations:
-
Acknowledgement of receipt: within 2 business days
-
Initial validation and classification: within 5 business days
- nformation about the further action plan: within 30 calendar days, where applicable
-
Status update: at least every 30 days while the matter remains open
-
Remediation, risk mitigation or security advisory: without undue delay, depending on the risk and complexity
The above timeframes are target timeframes and may change, in particular due to technical complexity, risks to users, dependencies on suppliers or the need to coordinate with relevant entities.
The reporter will be informed of any significant changes to the timeframe.
7. Assessment and remediationThe security team assesses each report in terms of its credibility, impact, exploitability, scale of impact and the availability of remedies. The assessment may take into account, among other factors, the Common Vulnerability Scoring System (CVSS), the product context and information about active exploitation.
- Vulnerabilities are recorded and tracked in a vulnerability management system, together with decisions, verification evidence and the status of actions taken.
- Remediation may include a security update, configuration change, workaround, removal of a component or other appropriate risk mitigation measures.
- In the case of third-party components, Merrid Controls will take reasonable steps to coordinate with the supplier or maintainer of the component and assess the impact on its own products.
8. Coordinated disclosure Merrid Controls aims to disclose vulnerabilities by agreement after a fix or effective risk mitigation measures have been made available. The standard expected coordination period is 90 days from receipt of a complete report, unless the parties agree on another timeframe or the risk requires faster communication.
- Public disclosures may include a description of the vulnerability, the affected products and versions, available fixes or workarounds, a CVE identifier, a risk assessment and attribution of the reporter, subject to the reporter’s consent.
- Merrid Controls may disclose limited information earlier if this is necessary to protect users, including in the event of active exploitation of the vulnerability.
- The reporter is requested not to publish details that would enable exploitation of the vulnerability before the agreed disclosure date, unless required by law.
9. CRA regulatory reportingIf the assessment shows that a vulnerability is being actively exploited or that an event meets the reporting criteria under the Cyber Resilience Act, Merrid Controls will initiate a separate assessment and reporting process involving the relevant entities, including through the applicable EU mechanisms.This obligation is fulfilled independently of communication with the reporter and does not require the public disclosure of technical details before measures to protect users have been implemented.
1
0. Recognition and rewardsMerrid Controls appreciates responsible vulnerability reports.With the reporter’s consent, Merrid Controls may include the reporter’s name, pseudonym or organisation in a security advisory or on a list of acknowledgements.This Policy does not establish a financial rewards programme. Any rewards are granted at Merrid Controls’ discretion and do not constitute an obligation.11. Data protectionPersonal data provided as part of a report is processed only to the extent necessary to handle the report, communicate with the reporter, fulfil legal obligations and protect product security.More information is available in the
Integrated Management System Policy.
12. Contact and reviewQuestions concerning this Policy should be submitted to:
cybersecurity@merrid.com.pl
The Policy is reviewed at least once every 12 months and following any significant change to processes, products or regulations, or any identified deficiency in the CVD process.
Appendix A — Change log
Version: 1.0
Date: 8 September 2026
Description of change: First edition
Approved by: Hubert Ladrowski, General Director