Bluefors Security and Vulnerability Disclosure Policy
Last updated on October 7, 2026
Introduction
This Policy sets out the coordinated vulnerability disclosure process maintained by Bluefors and our obligations under applicable cybersecurity laws and regulations.
This Policy explains how cybersecurity vulnerabilities and security incidents may be reported to Bluefors and how Bluefors manages reported vulnerabilities and communicates with reporters during investigation and remediation activities.
This Policy is published by Bluefors Oy (Finland). The Cryomech brand of cryocoolers and related products is manufactured and supported by Bluefors Cryocooler Technologies Inc., a Bluefors group company located in the United States. See “How to report a vulnerability?” below for where to direct reports concerning Cryomech-branded products
What is the scope of this Policy?
This section explains the scope of this notice.
This notice applies to:
- Bluefors products with digital elements, software and firmware ([email protected])
- Product web interfaces and APIs ([email protected])
- Bluefors-operated IT systems, online services, websites ([email protected])
This notice does not apply to:
- Third-party products or services not operated by Bluefors
- Physical penetration testing of Bluefors facilities
- Social engineering activities directed at Bluefors staff
- Denial-of-service testing
- Activities that may disrupt customer operations or physical equipment
What are security concerns and vulnerabilities?
This section explains what is meant by security and vulnerability.
Vulnerability – a weakness, susceptibility, or flaw in a product with digital elements, or in an information and communication technology (ICT) system, that can be exploited to compromise its confidentiality, integrity, availability, or authenticity.
Actively exploited vulnerability – a vulnerability for which there is reliable evidence that an unauthorized party has successfully exploited it in a system without the permission of the system owner.
Severe incident having an impact on the security of a product – an incident that negatively affects, or is capable of negatively affecting, the ability of a product to protect the confidentiality, integrity, availability, or authenticity of the product or of the data it processes.
Security incident – an event that compromises, or could compromise, the confidentiality, integrity, availability, authenticity, or continuity of Bluefors information and communication technology (ICT) systems or service
How to report a vulnerability?
This section explains where to report different types of cybersecurity concerns.
Product-related vulnerabilities and incidents (Bluefors-branded products)
If you believe you have identified a cybersecurity vulnerability or severe security incident affecting a Bluefors product, software application, firmware component, API, or digital service, please contact: [email protected]
Cryomech-branded products
Cryomech-branded cryocoolers and related products are manufactured and supported by Bluefors Cryocooler Technologies Inc., a Bluefors group company located in the United States. If you believe you have identified a cybersecurity vulnerability or severe incident having an impact on the security of a Cryomech-branded product, please notify Bluefors Cryocooler Technologies Inc. at: [email protected]. Regulatory notifications concerning reported vulnerabilities will be made by the responsible Bluefors group company in accordance with the EU Cyber Resilience Act or other applicable laws.
Corporate ICT security concerns
If your concern relates to Bluefors websites, employee accounts, corporate IT infrastructure, or internal information systems, please contact: [email protected]
Not sure?
If you are unsure which reporting channel is appropriate, reports may be submitted to either address and will be routed to the appropriate team.
What information should be included in the report?
This section explains the information required to investigate a reported vulnerability or security concern.
To support effective investigation and remediation, please include as much information as possible:
- Product, model, software version, firmware version, system, URL, or IP address affected
- Description of the issue
- Steps required to reproduce the issue
- Proof-of-concept code, screenshots, logs, or other supporting evidence
- Assessment of the potential impact
- Contact information for follow-up communication
Where sensitive information must be exchanged, Bluefors may arrange an alternative secure communication channel.
How do we handle reported vulnerabilities?
This section explains how Bluefors manages coordinated vulnerability disclose.
Upon receiving a report, Bluefors will:
- Assess the reported issue
- Request additional information where necessary
- Determine appropriate mitigation, remediation, and reporting actions
- Fulfil applicable regulatory reporting obligations under the EU Cyber Resilience Act and related national legislation, where required
- Communicate significant status updates to the reporter, where appropriate
- Inform the reporter when the case has been closed
- Make available corrective actions, updates, or fixed product releases where appropriate
Bluefors treats vulnerability reports and related communications as confidential and shares information only with personnel who require access to investigate, manage, remediate, or report the issue.
Advisories and notifications
Once a security update is available, Bluefors publishes information about the fixed vulnerability, including the affected products, the impact, the severity, and remediation guidance. In justified cases, Bluefors may delay publication until users have had the opportunity to apply the update. Advisories are made available on the bluefors.com website.
Bluefors will inform impacted users, and where appropriate all users, of actively exploited vulnerabilities or severe incidents having an impact on the security of their products, together with available mitigation measures, for example by email or on the Bluefors website.
Recognition
Bluefors does not offer monetary rewards, bug bounties, or finder’s fees for identifying or reporting a vulnerability.
Bluefors reserves the right not to publicly identify the reporter of a vulnerability, or to credit individuals, in connection with any remedial action taken.
Responsible disclosure
Bluefors supports coordinated vulnerability disclosure and requests that reporters:
- Act in good faith
- Avoid unauthorized access to systems, accounts, or data
- Avoid actions that could disrupt services, damage equipment, or affect the privacy of others
- Avoid testing against operational cryogenic, gas-handling, magnet, or other active customer systems
- Provide Bluefors with a reasonable opportunity to investigate and remediate reported vulnerabilities before public disclosure
- Comply with applicable laws and regulations
Thank you for helping keep Bluefors and our customers secure.