Coordinated Vulnerability Disclosure (CVD) Policy
Reporting a security vulnerability
Tool-Temp takes the security of its products seriously. If you believe you have found a security vulnerability in a Tool-Temp product (hardware, firmware, or software), we want to hear from you.
Contact: security@tool-temp.ch
Please include: product and firmware/software version, a description of the issue, steps to reproduce, and your contact details. We accept reports in English or German.
What we promise
- We will confirm receipt of your report promptly.
- A contact for follow-up while we investigate.
- No legal action against good-faith security research conducted in accordance with this policy.
- Credit in our security advisory, if you wish, once the issue is resolved.
What we ask
- Give us reasonable time to investigate and remediate before public disclosure — we will agree a disclosure timeline with you once the report is confirmed.
- Do not access, modify, or delete data belonging to others; do not degrade the operation of systems in productive use (our products control industrial thermal processes — testing against production equipment can cause physical damage).
- Do not use social engineering, physical intrusion, or denial-of-service testing.
Scope
All Tool-Temp products with digital elements (network, WLAN, or web-interface capable temperature control units and accessories) and their update mechanisms. Our corporate IT infrastructure is out of scope of this policy.
Our disclosure process
Confirmed vulnerabilities are remediated via firmware/software updates and published as security advisories on this page. Where legally required, we notify the relevant EU authorities in accordance with the Cyber Resilience Act (Regulation (EU) 2024/2847).
Last updated: 29.09.2026. Tool-Temp AG, Industriestrasse 30, 8583 Sulgen, Switzerland.
Coordinated Vulnerability Disclosure (CVD) Policy
Reporting a security vulnerability
Tool-Temp takes the security of its products seriously. If you believe you have found a security vulnerability in a Tool-Temp product (hardware, firmware, or software), we want to hear from you.
Contact: security@tool-temp.ch
Please include: product and firmware/software version, a description of the issue, steps to reproduce, and your contact details. We accept reports in English or German.
What we promise
- We will confirm receipt of your report promptly.
- A contact for follow-up while we investigate.
- No legal action against good-faith security research conducted in accordance with this policy.
- Credit in our security advisory, if you wish, once the issue is resolved.
What we ask
- Give us reasonable time to investigate and remediate before public disclosure — we will agree a disclosure timeline with you once the report is confirmed.
- Do not access, modify, or delete data belonging to others; do not degrade the operation of systems in productive use (our products control industrial thermal processes — testing against production equipment can cause physical damage).
- Do not use social engineering, physical intrusion, or denial-of-service testing.
Scope
All Tool-Temp products with digital elements (network, WLAN, or web-interface capable temperature control units and accessories) and their update mechanisms. Our corporate IT infrastructure is out of scope of this policy.
Our disclosure process
Confirmed vulnerabilities are remediated via firmware/software updates and published as security advisories on this page. Where legally required, we notify the relevant EU authorities in accordance with the Cyber Resilience Act (Regulation (EU) 2024/2847).
Last updated: 29.09.2026. Tool-Temp AG, Industriestrasse 30, 8583 Sulgen, Switzerland.