Coordinated Vulnerability Disclosure Policy

SATEL sp. z o.o. · version 1.1 · 9 September 2026 · change from 1.0: Art. 14 reporting deadlines clarified (§9) and the immediate-assessment rule (§5, §7)

1. Purpose

SATEL products protect people and property. Security researchers, installers and customers who find a weakness in them help us protect what those products are there to safeguard.

This document explains how to report a vulnerability to us, what we will do with your report, and what protection you have when you report in good faith.

This policy implements our obligation as a manufacturer under Regulation (EU) 2024/2847 (Cyber Resilience Act), Annex I Part II, which requires a documented coordinated vulnerability disclosure policy and a single point of contact.

2. Scope

In scope

All products and services placed on the market by SATEL:

Out of scope

We will acknowledge the following, but will not treat them as product vulnerabilities:

3. How to report

Preferred channel: the reporting form. It asks for the details we need to triage quickly and gives you a tracking ID.

Report a vulnerability

Fallback channel: psirt@satel.pl — if you cannot or prefer not to use the form.

Please do not report vulnerabilities through sales channels, installer technical support, or social media. Those routes are not monitored for security reports and will delay handling.

4. What to include

The more of this you can give us, the faster we can act:

Particularly important: tell us whether the vulnerability is already public, and whether you have any evidence that it is being exploited. That information changes our legal obligations and our timelines.

5. What we commit to

StageOur commitment
Acknowledgement of your reportwithin 72 hours
First technical assessmentwithin 10 working days
Status updates while we workat least every 14 days
Notification when a fix shipsyes, before public release where possible

Signals of active exploitation, a severe incident or a threat to users are assessed immediately, independently of the targets above. The preliminary legal qualification and the full technical assessment are two different stages — the first does not wait for the second.

If we conclude that a report is out of scope or is not a vulnerability, we will tell you so and explain why.

6. Safe harbour

If you make a good-faith effort to comply with this policy while researching and reporting a vulnerability, SATEL will:

This protection does not extend to conduct beyond good-faith research, in particular: accessing, modifying or exfiltrating other people's data; degrading or disrupting live systems that protect people or property; demanding payment in exchange for withholding a report.

If you are unsure whether something falls within these limits, ask us first. We would much rather answer a question than deal with the consequences.

7. What we ask of you

8. Recognition

We will credit you by name or handle in the advisory if you want that — say so in your report. You can also stay anonymous.

SATEL does not operate a paid bug bounty programme.

9. Our regulatory reporting

From 11 September 2026 we report actively exploited vulnerabilities contained in products covered by the CRA, and severe incidents having an impact on the security of those products, through the Single Reporting Platform (SRP) to the CSIRT designated as coordinator and to ENISA.

We submit the early warning without undue delay and at the latest within 24 hours of becoming aware, and the required follow-up notification without undue delay and at the latest within 72 hours of that same moment. For an actively exploited vulnerability we submit the final report at the latest 14 days after a corrective or mitigating measure has been made available; for a severe incident — within one month of the follow-up notification. Information already provided is taken into account.

Your report may be the source of the knowledge that triggers these obligations. This is one reason we ask whether you have evidence of exploitation.

We protect the reporter's identity and limit the processing of personal data to what is necessary; this does not preclude the lawful transfer of information to competent authorities.

10. Contact

SATEL sp. z o.o.
Product Security Team
psirt@satel.pl
https://cra.satel.pl/

11. Language versions

This policy is published in Polish and English. In case of any discrepancy between them, this English version prevails.