Coordinated Vulnerability Disclosure Policy

Nanoscribe welcomes reports of security vulnerabilities in our products. Security is part of how we build and support them, and reports from external researchers, customers and partners are a valued part of that. This policy explains how to report a vulnerability to us, what you can expect in return, and the terms under which we ask you to work with us.

Scope

This policy covers security vulnerabilities in Nanoscribe products that we have placed on the market: our 3D printing systems, their embedded software and firmware, and the Nanoscribe software applications delivered with them.

It does not cover our corporate IT and web infrastructure. If your finding concerns our website, our mail setup, leaked credentials, or someone impersonating Nanoscribe, please still write to the address below — we will route it to the responsible team internally.

How to report

  • Encryption: we do not publish a key. If you would prefer to submit encrypted, write to us without technical detail and we will arrange a channel with you.
  • Please include:

    • the affected product and version (and, if known, the affected component);
    • a description of the vulnerability and its impact;
    • step-by-step instructions or a proof of concept that lets us reproduce it, including any prerequisites such as network position or the privileges required;
    • how you would like to be credited, if you want to be named in a later advisory.
  • Languages: reports in English or German are welcome.

This address is intended for security vulnerability reports only. Please use our regular support channels for all other product enquiries.

What you can expect from us

  • Acknowledgement of your report within five business days.

  • Assessment of the report by our Product Security Incident Response Team (PSIRT). We may come back to you with questions if we need more detail to reproduce the issue.

  • Status updates while we work on the issue: for complex cases that need deeper investigation, approximately every 5 to 10 business days until it is resolved.

  • Coordination on disclosure. We will tell you how we intend to fix the issue and agree the timing of any public disclosure with you. Our default is disclosure as soon as a fix or a workaround is available, and in any case within 90 days of our acknowledgement. If an issue needs longer than that, we will explain why and agree a new date with you.

  • Credit, if you wish, in the advisory we publish for the fix.

Valid reports are handled under our documented internal vulnerability management process, which governs assessment, remediation, publication of user advisories, and — where an actively exploited vulnerability or a severe security incident is involved — our reporting obligations towards the authorities under the EU Cyber Resilience Act.

Security advisories. When a fix or workaround is available we notify affected customers directly. We also publish an advisory describing the vulnerability, the affected products and versions, the severity, and the remediation steps. Advisories are linked from this page. Where publication could increase risk to users before they can update, we may delay publication until users have had a reasonable opportunity to apply the fix.

We do not operate a bug bounty programme and do not offer payment for reports.

What we ask of you

  • Give us the 90 days described above – or the date we agree with you – to remediate the issue before disclosing it publicly.

  • Do not access, modify or delete data beyond the minimum needed to demonstrate the vulnerability, and do not degrade service for our users.

  • Only test against systems and installations that are your own or that you have explicit permission to test. Do not test against other customers’ systems.

  • Act in good faith and within the law, and treat any Nanoscribe or customer information you encounter as confidential.

Safe harbour

If you research and report in good faith and in accordance with this policy, we will treat your research as authorised. We will not pursue or support legal action against you in connection with your report, and we will make this position clear if a third party raises a claim about research conducted under this policy. If you are unsure whether a specific action is covered, ask us first at psirt@nanoscribe.com.

Login Register
Contact us
Close

It's your choice

Cookies help us to better understand you as a visitor and to provide you with a better experience.

It's your choice
Cookies help us to better understand you as a visitor and to provide you with a better experience.
Legal Notice Privacy Policy
Accept all Individual Settings