Security

Guidelines for the Coordinated Reporting of Security Vulnerabilities (CVD)

The security of our products and systems is a high priority for Variolytics GmbH. We welcome reports from customers, security researchers and other third parties regarding potential security vulnerabilities in our products.

Scope 

This policy applies to products with digital elements provided by Variolytics GmbH and the associated software, firmware and product-related digital components.
In Scope
  • EmiCo lite (connected measurement device)
  • EmiCo Insight (data processing platform, cloud, on-premises IPC, or customer VM)
  • Firmware and embedded software of the products listed above
  • Associated software components
  • Associated cloud services, where they form part of the product functionality
  • Associated web applications and APIs
  • Product-related interfaces and update mechanisms provided by Variolytics
  • Third-party and open-source components insofar as they form part of our products.
Out of scope
Unless expressly agreed otherwise, the following systems or activities are outside the scope of this policy:
  • Third-party systems or services that are not operated or controlled by Variolytics
  • Social engineering attacks against employees or contractors
  • Physical attacks against buildings, employees, devices or infrastructure
  • Denial-of-service or distributed denial-of-service testing
  • Spam, automated mass messaging or unnecessarily high automated request rates
  • Testing that may cause avoidable impairment of the availability, integrity or functionality of our products, systems or services.
If you are unsure whether a product, system or testing method is in scope, please contact us before carrying out further testing.

Reporting a Vulnerability

If you discover a potential vulnerability, please submit your report using the following contact details:

Security Email

security@variolytics.com

Recommended Subject Line

Security Vulnerability Report – [Product Name]

To enable us to analyze your report efficiently, please include as much of the following information as possible:
  • Affected product or component
  • Model, firmware or software version
  • Description of the vulnerability and the observed impact
  • Steps required to reproduce the issue
  • Where applicable, a proof of concept, logs, screenshots or other technical evidence
  • Tools and testing methods used, where relevant to reproduction
  • Date or time of discovery
  • Information on whether the vulnerability is already known to third parties
  • Any intended publication timeline
  • Contact information for inquiries.
Please do not submit personal data, confidential information or other protected information that is not necessary for analyzing the vulnerability.

How We Handle Your Report

We aim to acknowledge receipt of your report within 3 business days, assess the vulnerability, develop appropriate remediation measures, and coordinate the publication of information with the reporting party where possible.

Coordinated Disclosure

Please do not publish or share detailed information about an unresolved vulnerability without prior coordination with us. Variolytics will seek to address confirmed vulnerabilities without undue delay.

Treatment of Security Researchers

Where security research is conducted in good faith, within the scope of this policy and without malicious intent, Variolytics does not intend – to the extent legally permissible – to initiate legal action solely as a result of such security research. This statement does not constitute a general authorization to violate applicable law, contractual obligations or third-party rights.

Regulatory Reporting Obligations

Certain vulnerabilities or security incidents may be subject to statutory reporting obligations. Variolytics reserves the right to share information with competent authorities or CSIRTs to the extent required by law. This applies in particular to reporting obligations under Regulation (EU) 2024/2847 (Cyber Resilience Act).

Compensation

Variolytics does not currently operate a bug bounty programme.

Contact

Variolytics GmbH,
Ruppmannstraße 28,
70565 Stuttgart
security@variolytics.com
You can read the complete guideline (Version 1.0, approved) here.