Coordinated Vulnerability Disclosure Policy
1. Purpose
SATEL products protect people and property. Security researchers, installers and customers who find a weakness in them help us protect what those products are there to safeguard.
This document explains how to report a vulnerability to us, what we will do with your report, and what protection you have when you report in good faith.
This policy implements our obligation as a manufacturer under Regulation (EU) 2024/2847 (Cyber Resilience Act), Annex I Part II, which requires a documented coordinated vulnerability disclosure policy and a single point of contact.
2. Scope
In scope
All products and services placed on the market by SATEL:
- intruder alarm systems — INTEGRA, VERSA, PERFECTA, MICRA, BE WAVE
- wireless system ABAX 2
- communication and messaging modules (GSM/LTE, TCP/IP)
- access control — ACCO NET, ACCO
- fire alarm systems — CSP, ACSP
- alarm monitoring station software and receivers
- mobile applications and PC configuration software
- SATEL online services, including satel.pl
Out of scope
We will acknowledge the following, but will not treat them as product vulnerabilities:
- findings requiring physical destruction of a device beyond what an attacker could achieve undetected
- denial of service achieved purely through traffic volume
- missing HTTP headers, cookie flags or TLS settings on informational pages, with no demonstrated impact
- social engineering of SATEL staff, customers or installers
- raw output from automated scanners, with no analysis and no demonstrated impact
- vulnerabilities in third-party products we do not manufacture — please report those to their vendor, and tell us if a SATEL product is affected as a result
3. How to report
Preferred channel: the reporting form. It asks for the details we need to triage quickly and gives you a tracking ID.
Fallback channel: psirt@satel.pl — if you cannot or prefer not to use the form.
Please do not report vulnerabilities through sales channels, installer technical support, or social media. Those routes are not monitored for security reports and will delay handling.
4. What to include
The more of this you can give us, the faster we can act:
- product family, exact model or order code, and firmware/software version
- what access an attacker needs: the internet, the local network, physical access, or a third-party integration
- step-by-step reproduction instructions
- what an attacker achieves — the impact, not just the flaw
- proof of concept, if you have one
Particularly important: tell us whether the vulnerability is already public, and whether you have any evidence that it is being exploited. That information changes our legal obligations and our timelines.
5. What we commit to
| Stage | Our commitment |
|---|---|
| Acknowledgement of your report | within 72 hours |
| First technical assessment | within 10 working days |
| Status updates while we work | at least every 14 days |
| Notification when a fix ships | yes, before public release where possible |
Signals of active exploitation, a severe incident or a threat to users are assessed immediately, independently of the targets above. The preliminary legal qualification and the full technical assessment are two different stages — the first does not wait for the second.
If we conclude that a report is out of scope or is not a vulnerability, we will tell you so and explain why.
6. Safe harbour
If you make a good-faith effort to comply with this policy while researching and reporting a vulnerability, SATEL will:
- not pursue or support legal action against you in relation to your research;
- treat your research as authorised access for the purposes of any applicable computer misuse legislation;
- work with you if a third party takes action against you in relation to a report made under this policy.
This protection does not extend to conduct beyond good-faith research, in particular: accessing, modifying or exfiltrating other people's data; degrading or disrupting live systems that protect people or property; demanding payment in exchange for withholding a report.
If you are unsure whether something falls within these limits, ask us first. We would much rather answer a question than deal with the consequences.
7. What we ask of you
- Give us a reasonable opportunity to fix the issue before disclosing it. Our standard coordination window is 90 days from acknowledgement. If a fix needs longer — which happens with installed hardware — we will explain why and agree a date with you. The coordination window does not limit our reporting obligations or urgent warnings to users.
- Do not access, modify or delete data belonging to our customers.
- Do not test against installations that are not yours.
- Keep the details confidential until the coordination window ends, unless we agree otherwise.
8. Recognition
We will credit you by name or handle in the advisory if you want that — say so in your report. You can also stay anonymous.
SATEL does not operate a paid bug bounty programme.
9. Our regulatory reporting
From 11 September 2026 we report actively exploited vulnerabilities contained in products covered by the CRA, and severe incidents having an impact on the security of those products, through the Single Reporting Platform (SRP) to the CSIRT designated as coordinator and to ENISA.
We submit the early warning without undue delay and at the latest within 24 hours of becoming aware, and the required follow-up notification without undue delay and at the latest within 72 hours of that same moment. For an actively exploited vulnerability we submit the final report at the latest 14 days after a corrective or mitigating measure has been made available; for a severe incident — within one month of the follow-up notification. Information already provided is taken into account.
Your report may be the source of the knowledge that triggers these obligations. This is one reason we ask whether you have evidence of exploitation.
We protect the reporter's identity and limit the processing of personal data to what is necessary; this does not preclude the lawful transfer of information to competent authorities.
10. Contact
SATEL sp. z o.o.
Product Security Team
psirt@satel.pl
https://cra.satel.pl/
11. Language versions
This policy is published in Polish and English. In case of any discrepancy between them, this English version prevails.