At ERWEKA, we take the security of our products seriously. Cybersecurity is an integral part of how we design, develop and maintain our encoders and measurement solutions throughout their entire lifecycle. In line with the EU Cyber Resilience Act (CRA), we are committed to transparency about how we handle vulnerabilities and how they can be reported to us.
Below you will find our Coordinated Vulnerability Disclosure Policy, along with instructions on how to report a suspected vulnerability or security incident.
Adopted under Article 13(8) and Annex I, Part II, point 5 of Regulation (EU) 2024/2847 (Cyber Resilience Act).
ERWEKA GmbH welcomes reports of security vulnerabilities in its products with digital elements and handles them confidentially and promptly.
This policy covers all ERWEKA products with digital elements placed on the EU market, including their firmware, software and associated online services, for the duration of the applicable support period.
E-Mail
security@erweka.com
Languages
English, German
Please include: affected product and version, description of the issue, steps to reproduce, potential impact, and your contact details. Incomplete reports are welcome – report early rather than waiting for completeness.
| Step | Target |
| Acknowledgement of Receipt | 3 business days |
| Status Updates | At least every 30 days |
| Remediation (Critical Vulnerabilities) | 30 days |
| Publication of Advisory | After a fix is available |
We ask reporters to allow a reasonable remediation period – as a guideline 90 days – before public disclosure. Anyone who reports in good faith and in line with this policy will not face legal action from ERWEKA based on their research.
Where a report concerns an actively exploited vulnerability, ERWEKA is required to notify the competent CSIRT and ENISA within 24 hours. Please flag this explicitly if known to you.
Reports are treated confidentially and personal data is processed in line with the GDPR. No paid bug bounty programme exists; credit in the published advisory is offered on request.
Document control - ERWEKA GmbH Coordinated Vulnerability Disclosure Policy, version 1.0, effective 11 September 2026. Approved by Claus Elsner, CEO.
Questions about this policy: security@erweka.com
Single point of contact under Article 13(8) Regulation (EU) 2024/2847 (Cyber Resilience Act).
Email
security@erweka.com
Languages
English, German · anonymous reports accepted
Actively exploited?
Say so explicitly in your report – this triggers our 24-hour notification duty to the competent CSIRT / ENISA under Article 14 CRA.
Acknowledgement within 3 business days, regular status updates, and a coordinated disclosure timeline – details in our Coordinated Vulnerability Disclosure Policy (see above). Security updates are always free of charge.
Do: test only your own systems, report promptly, keep details confidential until disclosure is agreed.
Do not: access others' data, disrupt production systems, or request payment for your report.