Ampio’s CVD and product safety management policy

  • Document number: POL-011-EN
  • Version: 2.0
  • Date of publication: September 4, 2026


1. Purpose and scope of the policy

Reliability and security are the cornerstones of the Ampio system. This policy sets out the principles and process for Coordinated Vulnerability Disclosure (CVD) and the management of security incidents reported in Ampio’s hardware, firmware, mobile applications and cloud services.

The policy takes into account the requirements of Regulation (EU) 2024/2847, known as the Cyber Resilience Act, in particular with regard to the handling of vulnerabilities reported from internal and external sources and the coordinated disclosure of vulnerabilities.

2. Principles of responsible research and the protection of reporting parties

Ampio does not intend to take action against individuals who act in good faith and adhere to the following principles:

  • They report detected vulnerabilities without undue delay via the official Ampio channels specified in this policy or via the relevant CSIRT designated as the coordinator for the purposes of coordinated vulnerability disclosure.
  • They avoid infringing on users’ privacy, accessing logs or installation configurations, destroying data, and disrupting the operation of services (adhering to the no-DoS/DDoS policy).
  • They must avoid using social engineering attacks (phishing) against Ampio staff or users, and must not physically damage equipment.
  • They must maintain confidentiality and allow the Ampio team time to prepare and distribute a security patch before details are made public (known as Coordinated Vulnerability Disclosure).

3. How to report a vulnerability?

Reports are accepted via two channels:

Information required in the report

To ensure efficient analysis and verification, the report should include:

  1. Identification of the product or software (e.g. module name, PCB number, firmware version, application version).
  2. A detailed description of the vulnerability and the steps required to reproduce it (Proof of Concept).
  3. An assessment of the potential impact on system security or operational continuity.
  4. Information on whether the vulnerability has already been publicly disclosed or whether there are indications that it is being actively exploited (if known to the reporter).
  5. The report should not contain any confidential data, passwords, private access keys or data identifying end users of Ampio installations.

4. Report handling procedure and response times

  1. Confirmation of receipt: For reports sent to the dedicated email address security@cra.ampio.com or via the online form, confirmation of the report’s registration, together with the assigned case number, is sent automatically. The initial formal verification and contact from the security team will take place, where possible, within 48 hours (on working days) of receipt of the message.
  2. Verification and assessment: A preliminary technical analysis is carried out within 7 working days. Risk classification may be conducted using the CVSS scale and an internal assessment of the vulnerability’s impact on Ampio’s products, services and users.
  3. Vulnerability remediation: The R&D team develops appropriate remedial measures (security patch, firmware or software update). The turnaround time depends on the severity of the vulnerability and the complexity of the issue.
  4. Notification and distribution: Making updates available and, where justified, publishing a security advisory for users.

5. Mandatory reporting in accordance with the CRA Regulation

If Ampio becomes aware that a vulnerability in a product containing digital components is being actively exploited, or that a serious incident affecting the security of a product containing digital components has occurred, the report will be subject to an accelerated internal assessment process.

In such a case, the team designated by Ampio to handle security reports will assess whether the incident is subject to a reporting obligation in accordance with Regulation (EU) 2024/2847 of 23 October 2024 – the Cyber Resilience Act.

If a reporting obligation applies, Ampio will make the required notifications via the Single Reporting Platform, to the CSIRT designated as the coordinator and to ENISA, in accordance with the relevant regulations and deadlines, in particular:

  • early warning – without undue delay, no later than within 24 hours of becoming aware of the incident;
  • full notification – without undue delay, no later than within 72 hours of becoming aware of the incident;
  • final report – within the timeframe required by the relevant regulations, depending on the nature of the incident.

The reporting deadlines under the CRA are independent of the indicative timeframes for communication with the reporter set out in this policy.

6. Device support lifecycle and updates

Ampio determines the security support period for products containing digital components, taking into account their expected service life, the nature of the product, its intended use and the reasonable expectations of users.

During the support period, Ampio will provide security updates or other risk-mitigation measures for supported products, in accordance with the applicable requirements of European Union law.

Information on the support period for individual products or product groups are published in the product documentation, the General Warranty Terms and Conditions, security bulletins or on the Ampio website.