Coordinated Vulnerability Disclosure
Version 1.0 · Last updated 4 Sept 2026
About this policy
OpenSynergy GmbH, incl. OpenSynergy, Inc. (hereinafter referred to as “OpenSynergy” or “we”) develops embedded software products that our customers integrate into their own products. Security vulnerabilities in our software can affect the products our customers build, and the people who use them.
We want to hear about vulnerabilities in our software. This policy explains how to report one, what we do when we receive your report, and how we handle publication. It applies equally to our customers, to the companies that use or integrate our software, and to independent security researchers.
What this policy covers
What to include in a report
The more information you can give us, the faster we can assess your report:
-
the product, and the version, build or configuration affected
-
a description of the vulnerability and what an attacker could achieve
-
the conditions under which it occurs
-
the steps needed to reproduce it, and any proof-of-concept material
-
your assessment of impact and severity
-
any other products, components or suppliers you believe are affected
-
whether you have reported this to anyone else, including but not limited to other suppliers or a disclosure coordinator (e.g., CSIRT, ENISA, CVE Program)
-
whether you intend to publish, and on what timescale
-
your name and affiliation, and how you would like us to contact you
If you cannot supply all of this, send what you have.
This Policy covers our software product portfolio as available in the “Products” section of www.opensynergy.com.
You can report a vulnerability in any version of these products, whether or not that version is still supported. We welcome such reports.
Whether we provide a correction depends on whether the affected version is still within its cybersecurity support period. That period is at least five years from the date the product was placed on the market, whereas this period may be extended upon agreement. The end date for a specific product version is stated in the information supplied with the product and is available from us on request at the address in section “How to report”. Security updates issued within the support period are provided free of charge.
Corrections are supplied through the normal delivery channel for the product concerned. Because our software is integrated by our customers into their own products, we cannot deliver a correction directly to the end user of a finished product.
What this policy does not cover
This policy covers our software products only.
If you have found a security problem in our website or our corporate IT systems, please write to security@opensynergy.com instead (PGP Key keys.openpgp.org/vks/v1/by-fingerprint/E40332C7312FFFC3C1EC847CD37AC1F32C7B5AD5). Those reports are handled separately and are not covered by this policy.
This policy also does not cover any product, device or vehicle built by a customer using our software. Section “Research carried out in good faith” sets out what is Out of scope for testing.
Functional problems with no security impact are not handled under this policy. If you are a customer, please raise those through your normal support channel.
If your concern is about the safe operation of a product rather than a security vulnerability, send it to the address in section “How to report” and we will route it.
How to report
Send your report to psec@opensynergy.com (PGP Key keys.openpgp.org/vks/v1/by-fingerprint/4B063014B73EFC4E93F37D423083C331C31E059A).
Please write in English.
Please include your name and contact details. We do not take forward reports we are unable to follow up on.
To protect sensitive information, we recommend encrypting your report using PGP before sending. Please use mentioned PGP key above.
Before encrypting please verify email and fingerprint of the downloaded PGP key:
email: psec@opensynergy.com
fingerprint: 4B06 3014 B73E FC4E 93F3 7D42 3083 C331 C31E 059A
Please do not include sensitive personal data, customer data, or confidential information belonging to a third party. If demonstrating the issue requires such material, tell us and we will agree on how to handle it.
What we do when we receive a report
Acknowledgement. We acknowledge the receipt of reports within seven calendar days. The acknowledgement gives you a tracking reference and the initial status of your report.
Assessment. We assess every report we receive. If your report does not contain enough information for us to assess it, we will contact you to request additional information. If we do not hear back, we may close the report.
Outcome. Once our assessment concludes we tell you the result: whether we have confirmed a vulnerability in our software, whether the issue lies elsewhere, or whether we do not consider it a vulnerability. Where we confirm a vulnerability, we will tell you when a correction becomes available.
We do not commit to a timeframe for producing a correction. How long it takes depends on the nature of the vulnerability, and we prefer not to provide estimates that we may be unable to meet.
Confidentiality
We treat your report as confidential.
We share the technical details with those who need them to assess and correct the vulnerability, with the customers affected, and where a CVE identifier is requested. We do not pass your name or contact details outside OpenSynergy and its affiliated companies without your agreement.
Where we are legally required to notify a public authority about a vulnerability, we will do so. A notification of that kind goes to the authority concerned; it does not make your report public.
We ask you to treat the vulnerability as confidential until publication has been agreed, as described in section “Disclosure timing”.
Disclosure timing
We do not apply a fixed embargo period. We agree the timing with you.
Our normal approach has two stages. First a confidential stage, in which the customers affected are informed so they can assess their exposure and act, then publication. The confidential stage has to be long enough for our customers to do something useful with the information, and no longer.
Because our software is integrated into other companies' products, the time needed for a correction to reach the people who ultimately use those products is often longer than for software shipped directly to end users. Where that is the case we will explain it to you rather than leave the report without further updates.
Where you intend to publish, we would prefer our publication and yours to happen at the same time, and we will work with you towards that.
If you decide to publish before coordination has concluded, it is your decision. It does not change our commitment under this Policy, but it may mean we publish earlier than planned so our customers are not left without guidance.
Security advisories
We issue a security advisory for each confirmed vulnerability once a correction is available.
The customers affected receive the full advisory through the normal channel for the product concerned. It identifies the affected products and versions, describes the vulnerability and its impact in adequate detail to judge exposure, gives a severity rating, and states what to do.
We also publish a public notice at www.opensynergy.com/security-advisories. The public notice identifies the product and the versions affected, confirms that a correction is available, and carries the identifier assigned to the vulnerability. It contains less technical detail than the customer advisory.
Each advisory and notice carries its own reference and a publication date.
Where a vulnerability qualifies for a CVE identifier, we request one and include it in the advisory.
Where a vulnerability is being actively exploited and no correction is yet available, we may publish earlier so that customers and users can protect themselves in the meantime.
Vulnerabilities in third-party and open-source components
Our products include third-party and open-source components.
If your report concerns such a component and we confirm that one of our products is affected, we take it up with the supplier or the upstream project as part of handling the report, and coordinate publication accordingly.
If we conclude that none of our products is affected, we will tell you. We will not usually pass the report on in that case, so if you want the issue addressed, please report it to the party responsible for the component directly.
Recognition
Should we proceed with the publication of an advisory based on your report, we would be pleased to credit you accordingly. Please advise us whether you would prefer to be named or to remain anonymous.
We do not operate a bug bounty program, and we do not offer payment or other rewards for reports.
Safe Harbor
We value the work of independent security researchers and want to encourage a safe, mutually respectful environment for vulnerability reporting.
If you make a good-faith effort to comply with this policy, especially and the limits in section “Out of scope for testing” and “What this policy does not cover”, during your security research, we will view your research as authorized. We will not initiate or support any legal action, civil lawsuits, or criminal complaints against you related to your research.
This Safe Harbor applies exclusively to products owned and operated by OpenSynergy as explicitly listed within the scope of this policy, see section “What this policy covers”. If your research involves services, cloud providers, device or vehicle operated by a customer or anyone else, or software owned by a third party, that third party may choose to pursue legal action at their own discretion. We cannot waive legal liability on behalf of third parties.
Safe Harbor is strictly void and does not apply if you (i) act with malicious intent; (ii) seek financial gain through extortion, ransom, or threats of disclosure; (iii) intentionally cause harm, disruption, or damage; or (iv) knowingly violate applicable laws.
For the avoidance of doubt, the activities that are not authorized under this policy are listed in the section "Out of scope for testing" and are excluded from this Safe Harbor.
Out of scope for testing
The following are not authorized under this policy:
-
any system, device or vehicle operated by a customer or third party, including ones containing our software
-
our website, our corporate IT systems and accounts, and services operated by our suppliers — if you become aware of a problem in these, see section “What this policy does not cover”
-
physical attacks, and any activity directed at our premises
-
social engineering or phishing, and any activity directed at our staff, customers or partners as individuals
-
denial-of-service, stress and load testing
-
accessing, modifying, deleting or copying data that does not belong to you, and using access gained in one system to reach another
We are also unlikely to act on output from automated scanning tools where no impact has been demonstrated, general observations about configuration or hardening with no realistic attack shown, or theoretical weaknesses with no practical route to exploitation.
Changes to this policy
We may revise this policy at any time. The version in force is the one published at www.opensynergy.com/vulnerability-disclosure-policy.
