Coordinated Vulnerability Disclosure (CVD) Policy
At Thermoplan, the security of our products, systems, and customer data is a top priority. We recognize the important role that independent security researchers play in keeping the digital ecosystem safe.
If you believe you have found a security vulnerability in a Thermoplan product or system, we encourage you to report it to us to help us improve our security.
1. Safe Harbor (Legal Protection)
We consider activities conducted consistent with this policy to constitute "authorized" conduct. We will not initiate legal action or file a complaint with law enforcement against researchers who:
- Follow this policy and make a good faith effort not to interrupt or degrade our services.
- Do not access, modify, delete, or store sensitive corporate data, credentials, or proprietary information beyond what is strictly necessary to demonstrate the vulnerability.
- Keep the vulnerability details confidential until we have mutually agreed on a timeframe for public disclosure.
We cannot, however, bind third parties or prevent law enforcement from acting independently if legal boundaries are crossed.
2. Scope
This policy applies to:
- All web services hosted on thermoplan.ch, *.thermoplan.ch, *.thermoplan.com, *.thermoplanconnect.com .
- Thermoplan hardware products, embedded software, and IoT interfaces currently supported by us.
Out of Scope (Please do NOT test):
- Physical attacks against Thermoplan facilities or property.
- Social Engineering (e.g., Phishing, Vishing) against Thermoplan employees or contractors.
- Volumetric attacks (e.g., DDoS).
- Third-party services or vendors not directly managed by Thermoplan.
- Aggressive automated scanning or testing that generates significant traffic and could degrade our services
3. Reporting a Vulnerability
Please send your findings to our dedicated security team at: security@thermoplan.ch
To help us triage and resolve the issue quickly, please include:
- A clear description of the vulnerability and its potential impact.
- Detailed steps to reproduce the issue (including URLs, parameters, or specific product firmware versions).
- Proof of Concept (PoC) code or screenshots, if available.
4. Our Commitment
When you submit a vulnerability report according to this policy, we commit to the following:
- Acknowledgment: We will acknowledge receipt of your report within 3 business days.
- Assessment: We will triage the vulnerability and provide you with updates on our remediation progress upon request.
- Recognition: With your permission, we will gladly recognize your contribution in our release notes once the vulnerability has been remediated.
We strictly adhere to a coordinated disclosure process. Please do not publish details of the vulnerability before 90 days after we have released a patch, firmware update, or official mitigation. Please note that Thermoplan does not currently operate a paid Bug Bounty program. We offer recognition, but no financial compensation for vulnerability reports.