Bluefors Security and Vulnerability Disclosure Notice
Last updated on September 11, 2026
Introduction
This Notice supports the coordinated vulnerability disclosure process maintained by Bluefors and our obligations under the EU Cyber Resilience Act (Regulation (EU) 2024/2847).
This Notice explains how cybersecurity vulnerabilities and security incidents may be reported to Bluefors and how Bluefors manages reported vulnerabilities and communicates with reporters during investigation and remediation activities.
What is the scope of this Notice?
This section explains the scope of this notice.
This notice applies to:
- Bluefors products with digital elements, software and firmware ([email protected])
- Product web interfaces and APIs ([email protected])
- Bluefors-operated IT systems, online services, websites ([email protected])
This notice does not apply to:
- Third-party products or services not operated by Bluefors
- Physical penetration testing of Bluefors facilities
- Social engineering activities directed at Bluefors staff
- Denial-of-service testing
- Activities that may disrupt customer operations or physical equipment
What are security concerns and vulnerabilities?
This section explains what is meant by security and vulnerability.
Actively exploited vulnerability – A vulnerability for which there is reliable evidence that an unauthorized party has successfully exploited the vulnerability.
Severe vulnerability incident – situations where a vulnerability event affects the availability, authenticity, integrity or confidentiality of a product. An incident may be severe.
Security incident – an event that compromises, or could compromise, the confidentiality, integrity, availability, authenticity, or continuity of Bluefors information and communication technology (ICT) systems or services.
How to report a vulnerability?
This section explains where to report different types of cybersecurity concerns.
Product-related vulnerabilities and incidents
If you believe you have identified a cybersecurity vulnerability or severe security incident affecting a Bluefors product, software application, firmware component, API, or digital service, please contact: [email protected]
Corporate ICT security concerns
If your concern relates to Bluefors websites, employee accounts, corporate IT infrastructure, or internal information systems, please contact: [email protected]
If you are unsure which reporting channel is appropriate, reports may be submitted to either address and will be routed to the appropriate team.
What information should be included in the report?
This section explains the information required to investigate a reported vulnerability or security concern.
To support effective investigation and remediation, please include as much information as possible:
- Product, model, software version, firmware version, system, URL, or IP address affected
- Description of the issue
- Steps required to reproduce the issue
- Proof-of-concept code, screenshots, logs, or other supporting evidence
- Assessment of the potential impact
- Contact information for follow-up communication
Where sensitive information must be exchanged, Bluefors may arrange an alternative secure communication channel.
How do we handle reported vulnerabilities?
This section explains how Bluefors manages coordinated vulnerability disclose.
Upon receiving a report, Bluefors will:
- Assess the reported issue
- Request additional information where necessary
- Determine appropriate mitigation, remediation, and reporting actions
- Fulfil applicable regulatory reporting obligations under the EU Cyber Resilience Act and related national legislation, where required
- Communicate significant status updates to the reporter, where appropriate
- Inform the reporter when the case has been closed
- Make available corrective actions, updates, or fixed product releases where appropriate
Bluefors treats vulnerability reports and related communications as confidential and shares information only with personnel who require access to investigate, manage, remediate, or report the issue.
Responsible disclosure
Bluefors supports coordinated vulnerability disclosure and requests that reporters:
- Act in good faith
- Avoid unauthorized access to systems, accounts, or data
- Avoid actions that could disrupt services, damage equipment, or affect the privacy of others
- Avoid testing against operational cryogenic, gas-handling, magnet, or other active customer systems
- Provide Bluefors with a reasonable opportunity to investigate and remediate reported vulnerabilities before public disclosure
- Comply with applicable laws and regulations
Thank you for helping keep Bluefors and our customers secure.