COORDINATED VULNERABILITY DISCLOSURE POLICY
CAQ AG Factory Systems - Last updated: 24 August 2026 - Version 1.0
1. PURPOSE AND SCOPE
CAQ AG Factory Systems ("CAQ") takes the security of its products seriously.
This policy describes how security researchers, customers, partners and other third parties can report potential vulnerabilities in our products, and how CAQ handles such reports. It implements the requirements of Annex I Part II of the Cyber Resilience Act (Regulation (EU) 2024/2847) as well as BSI TR-03183-1 and ISO/IEC 29147.
We expressly welcome reports about security vulnerabilities and treat every report as confidential.
2. PRODUCTS COVERED
This policy applies to the products developed and placed on the market by CAQ, in particular the software suite CAQ.Net including all associated modules and bundled components.
Out of scope are, for example:
- products and services of third parties not maintained by CAQ
- attacks aimed at impairing availability (DoS/DDoS)
- social engineering against CAQ employees or customers
- purely theoretical vulnerabilities without credible evidence of exploitability
3. HOW TO REPORT (CONTACT)
Please send reports to:
- Reporting page: https://www.caq.net/security
- Reference: Machine-readable contact details are available at https://www.caq.net/.well-known/security.txt
Transmission is protected in transit (TLS). Additional end-to-end encryption is not required.
4. WHAT TO INCLUDE IN A REPORT
To help us assess your report quickly, please provide where possible:
- the affected product and, if known, the affected version(s)
- a description of the vulnerability and its potential impact
- steps to reproduce (proof of concept, configuration, logs)
- where possible, an assessment of the severity
- your contact details for follow-up questions (anonymous if you prefer)
5. OUR COMMITMENTS
As part of a coordinated disclosure, CAQ commits to:
- acknowledge receipt of a report within 5 business days;
- assess the report (triage) and inform you of its status on request;
- remediate confirmed vulnerabilities without undue delay and provide affected customers with security updates or mitigation guidance;
- once a corrective measure is available, publish a description of the vulnerability (security advisory, including a CVE identifier where applicable);
- treat your report as confidential and, if you wish, credit you as the finder upon publication.
6. EXPECTATIONS OF REPORTERS
In the spirit of coordinated disclosure, we ask that you:
- do not disclose details of the vulnerability publicly until a corrective measure is available or a mutually agreed deadline has expired;
- do not access, modify, delete or publish third-party data, and act only to the extent necessary to demonstrate the vulnerability;
- do not impair the availability or integrity of our systems or those of our customers.
7. GOOD-FAITH SECURITY RESEARCH (SAFE HARBOUR)
Anyone acting in good faith and in accordance with this policy need not fear legal action from CAQ. CAQ considers such activities to be authorised and
supports responsible security research. This commitment does not exempt anyone from complying with applicable law towards third parties.
8 PROCESS AND TIMELINE
- 1. Receipt & acknowledgement - within 3 business days.
- 2. Triage & verification - assessment, severity rating, confirmation.
- 3. Remediation - development, testing and release of a corrective measure.
- 4. Disclosure - coordinated publication after the fix is available, generally within 90 days of confirmation. Different timelines may be agreed on a case-by-case basis.
If a reporter discloses details prematurely, or if a vulnerability is shown to be actively exploited, CAQ may accelerate remediation and disclosure.
9. RELATIONSHIP TO STATUTORY REPORTING OBLIGATIONS
If CAQ becomes aware that a reported vulnerability is being actively exploited,or that a severe security incident has occurred, CAQ will additionally fulfil
its reporting obligations under Article 14 CRA towards the competent CSIRT and ENISA. This statutory reporting takes place independently of the status of the coordinated disclosure.
10. CONTACT AND CHANGES
This policy is maintained by the Product Security Incident Response Team (PSIRT) of CAQ AG. This policy may be updated; the version published at the address above is authoritative.
This policy is a publicly accessible document within the meaning of Annex I Part II of the Cyber Resilience Act and BSI TR-03183-1 (REQ_VH 5).