INNOVATEST website header

Product Security

Report a Security Vulnerability

The security of INNOVATEST products and the protection of our customers are important to us. We welcome responsible reports from customers, distributors, security researchers and other parties who believe they have discovered a potential security vulnerability.

This page explains how to report a vulnerability and how INNOVATEST handles reported security issues.

How to Report a Vulnerability

Please report potential security vulnerabilities through one of the following channels:

Email: security@innovatest-europe.com

Please do not use the general sales or service contact form or channels for security vulnerabilities.

What Can Be Reported?

You can use this reporting channel for potential vulnerabilities involving:

  • INNOVATEST hardness testers;
  • INNOVATEST desktop and mobile applications;
  • INNOVATEST websites, portals and online services;

For ordinary technical problems, calibration questions, software installation assistance or warranty requests, please contact our regular support team.

 

Information to Include

Please provide as much of the following information as possible:

  • Product name and model;
  • Serial number, if available;
  • Installed software or firmware version;
  • Operating system version;
  • Description of the potential vulnerability;
  • Steps needed to reproduce the issue;
  • Expected and observed behaviour;
  • Possible security impact;
  • Relevant network configuration;
  • Screenshots, log files or diagnostic information;
  • Whether you believe the vulnerability is being actively exploited;
  • Whether the information has already been shared with another party.

Please remove passwords, customer measurement data and unnecessary personal information before submitting files.

What Happens After You Report?

After receiving a vulnerability report, INNOVATEST will:

  1. Acknowledge receipt of the report within [two business days];
  2. Perform an initial assessment and assign an internal reference number;
  3. Contact the reporter when additional information is required;
  4. Investigate the affected product and supported versions;
  5. Determine the severity, impact and required corrective measures;
  6. Develop and verify a security update or other mitigation where necessary;
  7. Coordinate communication and disclosure with the reporter;
  8. Inform affected customers and distributors when appropriate;
  9. Publish a security advisory after a corrective measure is available, unless publication needs to be temporarily delayed to protect customers.

Resolution time depends on the complexity, severity and impact of the vulnerability. INNOVATEST will provide reasonable status updates while the investigation remains active.

Coordinated Vulnerability Disclosure Policy

We ask security researchers to follow these principles:

  • Report the vulnerability privately and without unnecessary delay;
  • Give INNOVATEST a reasonable opportunity to investigate and correct the issue before publication;
  • Only access systems, devices and data for which you have explicit authorisation;
  • Limit testing to what is necessary to demonstrate the vulnerability;
  • Avoid disruption of production, measurement or safety-related processes;
  • Do not alter or delete data;
  • Do not install persistent access mechanisms;
  • Do not download more data than is necessary to demonstrate the issue;
  • Do not share credentials, personal data, customer data or confidential information;
  • Stop testing and contact us immediately if sensitive information is accessed;
  • Coordinate any public disclosure with the INNOVATEST support team.

Prohibited Testing

The following activities are not authorised under this policy:

  • Denial-of-service or resource-exhaustion testing;
  • Testing that could affect machine safety or measurement integrity;
  • Testing on customer or production systems without written permission;
  • Physical damage to products or equipment;
  • Social engineering, phishing or impersonation;
  • Attempts to access employee or customer accounts;
  • Introduction of malware;
  • Modification or destruction of data;
  • Testing of third-party products or services that are not controlled by INNOVATEST.

This policy does not grant permission to perform security testing where you do not otherwise have authorisation.

Good-Faith Security Research

When you act in good faith, comply with this policy and make a reasonable effort to prevent harm, INNOVATEST does not intend to initiate legal action solely because of your security research.

If you are unsure whether your intended testing is permitted, contact service@innovatest-europe.com before proceeding.

 

Confidentiality and Public Disclosure

Please keep vulnerability information confidential until:

  • INNOVATEST has completed its investigation;
  • A security update or mitigation has been made available where necessary; and
  • A coordinated publication date has been agreed.

INNOVATEST may publish information about resolved vulnerabilities, including:

  • Affected products and versions;
  • A description of the vulnerability;
  • Its severity and potential impact;
  • Available security updates;
  • Workarounds or mitigating measures;
  • Actions customers should take.

INNOVATEST may delay publication when early disclosure could increase the cybersecurity risk to customers.

Security Updates and Product Support

Security updates addressing identified cybersecurity vulnerabilities are provided free of charge during the applicable product support period. Security updates are separate from functional enhancements, optional features or paid software upgrades.

During the applicable product support period, INNOVATEST provides information about relevant security updates and corrective measures. Customers should install security updates within the recommended timeframe, even when the product appears to be functioning normally.

Some software and firmware updates must be installed by an authorised INNOVATEST service engineer. Contact INNOVATEST or your authorised distributor for the correct installation procedure.

 

Personal Data

Personal data included in a vulnerability report will only be used to:

  • Investigate and resolve the reported issue;
  • Communicate with the reporter;
  • Coordinate security updates and disclosure;
  • Meet applicable legal and regulatory obligations.

Please refer to our Privacy Policy for further information.

Contact

INNOVATEST Europe B.V.
Borgharenweg 140
6222 AA Maastricht
The Netherlands

Product Security: security@innovatest-europe.com
Telephone: +31 43 352 00 60
General support: service@innovatest-europe.com