Coordinated Vulnerability Disclosure (CVD) Policy

Company: Silicann Systems GmbH

Effective date: September 1, 2026

Version: 1.0

1. Introduction and Purpose

The security of our products is of the highest priority for Silicann Systems GmbH. In accordance with the requirements of the EU Cyber Resilience Act (Regulation EU 2024/2847), we are committed to transparent and responsible handling of security vulnerabilities. This policy governs how security researchers, customers, and third parties can safely report vulnerabilities in our products, and how we coordinate and remediate them.

2. Scope

This policy applies to all products with digital elements developed, provided, and commercially offered on the market by Silicann Systems GmbH, including embedded software, associated applications, and provided updates.

  • Commercial Open-Source Software: This scope explicitly extends to open-source software provided by us on public platforms (e.g., GitHub), insofar as this software is distributed as part of our business activities, serves as the basis for our commercial products, or we offer paid support for it.
  • Third-Party / Upstream: Should a vulnerability be found in an open-source component or third-party software library used by us that is not maintained by us, we will coordinate the remediation with the respective maintainers in order to secure our products.

3. How to Report a Vulnerability

If you have discovered a potential security vulnerability in one of our products, we ask you to report it to us immediately.

Reporting channel: Please send an email to security@silicann.com

Encryption (Recommended): For secure transmission, please use our PGP key. You can find the key and current contact details in our security.txt at https://silicann.com/.well-known/security.txt.

Content of the report: To enable us to assess the vulnerability as quickly as possible, your report should include the following information:

  • Affected product and version number.
  • A detailed description of the vulnerability.
  • Step-by-step instructions or proof-of-concept (PoC) for reproduction.
  • Potential impact of the vulnerability.

4. Our Commitment (Safe Harbor / Legal Assurance)

We value the work of security researchers. If you adhere to the following rules, we will not take legal action against you:

  • You do not access, modify, or delete customer data.
  • You do not conduct denial-of-service attacks (DoS/DDoS) or social engineering attacks.
  • You do not disclose the vulnerability to third parties or the public before we have had the opportunity to remediate it (Coordinated Disclosure).

Note: Silicann Systems does not operate a bug bounty program with financial rewards.

5. The CVD Process and Response Times

Upon receipt of a report, our IT Officer initiates the following process:

  • Acknowledgement of receipt: We confirm receipt of your report within a maximum of 48 hours.
  • Validation: We technically review and analyze the vulnerability. If necessary, we will contact you for further inquiries.
  • Remediation: We promptly develop a patch, firmware update, or risk-mitigating measure (workaround).
  • Transparency: After successful remediation, the finder will – if desired – be credited by name in the release notes.

6. Customer Notification (B2B Communication)

As we serve an exclusive number of corporate customers, the provision of security updates and information does not occur via public channels but instead in a targeted and direct manner:

In the event of a validated, critical vulnerability and the availability of a patch, all affected customers will be contacted manually and directly via email by our IT Officer.

The email will include a clear risk assessment, instructions for installing the update, and, if necessary, temporary workarounds to protect the systems.