top of page

Vulnerability Disclosure Policy

Reporting security vulnerabilities in hardware or software products

Tpa follows a Coordinated Vulnerability Disclosure (CVD) process designed to ensure that vulnerabilities are analysed, rectified and disclosed in a coordinated and responsible manner, in accordance with applicable European cybersecurity regulations (EU Regulation 2024/2847).

Please report any potential vulnerabilities in our hardware and software products to us. Further information on reporting vulnerabilities can be found in the guidelines below.

Please note: If you wish to report a potential vulnerability relating to our website or our applications, please contact us at security[AT]tpaspa.it.

Vulnerability Disclosure Policy

As a manufacturer of hardware and software products for industrial automation, cybersecurity is a core component of Tpa’s values.

Tpa is therefore committed to ensuring the security of users of Tpa hardware and software products by protecting their privacy and information. As Tpa values the contribution of external security researchers who assist us in good faith to maintain a high standard of security for our users and systems, this policy aims to provide security researchers with clear guidance on how to conduct vulnerability disclosure activities and to outline our preferred methods for reporting discovered vulnerabilities.

We invite you to contact us promptly to report any security vulnerabilities in our products.

Legitimacy

Reported vulnerabilities will be assessed and managed through Tpa’s internal vulnerability handling process. Where applicable, Tpa will comply with the notification obligations set out in Regulation (EU) 2024/2847 (Cyber Resilience Act). Provided you act in good faith and comply with this policy in your security research, Tpa will handle your reports responsibly and will seek to collaborate with the person who reported the vulnerability to understand and ultimately resolve the issue.

Where the vulnerability concerns components, software or services provided by third parties and integrated into Tpa’s products, the company may coordinate with the relevant parties for the management and responsible disclosure of the vulnerability.

Coordinated disclosure of vulnerabilities

Tpa promotes the co-ordinated and responsible disclosure of security vulnerabilities. We ask researchers not to publicly disclose the details of a reported vulnerability before Tpa has had the opportunity to analyse it, assess the associated risks and, where necessary, develop and distribute appropriate corrective measures.

Tpa is committed to cooperating in good faith with the reporter throughout the vulnerability management process and, where appropriate, to agreeing on the manner and timing of public disclosure in a way that minimises risks to customers, users and other stakeholders.

Safe harbor

Tpa will not take legal action against researchers who conduct research in good faith, in accordance with this policy, and to the extent necessary to identify and demonstrate the existence of a security vulnerability.

Important information

In this policy, ‘research’ refers to activities in which:

  • you inform us as soon as possible when you discover an actual or potential security issue,

  • you make every effort to prevent data breaches, degradation of the user experience, disruption to production systems, and the destruction or manipulation of data,

  • you use exploits only to the extent necessary to confirm the existence of a vulnerability. Do not use exploits to compromise or extract data, gain persistent command-line access, or use the exploit to move to other systems.

Once you have identified a vulnerability or encountered sensitive data (including personal, financial or proprietary data, or trade secrets of any party), you must stop testing, report it immediately and not disclose such data to third parties.

Scope of application

This policy applies to the following systems and services:

hardware, software and firmware products marketed by Tpa.

Vulnerabilities will be managed throughout the product’s stated support period.

Reporting a vulnerability

The information provided under this policy is used solely for defensive purposes to mitigate or resolve vulnerabilities. If your findings contain new vulnerabilities that affect all users of a product or service – and not just Tpa – we may disclose your report to relevant parties such as suppliers, partners, distributors or customers, without your explicit consent.

Reports can be sent to the email address security[AT]tpaspa.it, including anonymously.

Reporting guidelines

To help us classify and prioritise reports, we recommend that you include the following in your report:

  • a description of the issue,

  • the item code and serial number of the product in question (if hardware),

  • the product name and version (if software),

  • a description of the environment in which the vulnerability was discovered and its potential impact,

  • a detailed description of the steps required to reproduce the vulnerability (scripts, proof-of-concepts or screenshots are helpful).

What you can expect from us/Response times

As soon as you provide us with your contact details, we are committed to communicating with you as quickly and openly as possible.

Tpa will confirm receipt of the report without undue delay and, where possible, will maintain regular communication with the reporter throughout the vulnerability analysis and management process.

bottom of page