Coordinated Vulnerability Disclosure Policy
Essensium NV — Version 1.0 Gaston Geenslaan 10, 3001 Leuven, Belgium
1. Purpose
Essensium designs and manufactures safety-critical systems for industrial environments. We treat security vulnerabilities in our products as a safety matter. This policy sets out how you can report a vulnerability to us, what we commit to in return, and how we handle disclosure.
We welcome reports from security researchers, customers, integrators and the wider public.
2. Scope
This policy covers all SafeTrack system v3.2 products with digital elements, for the entire support period. This includes:
Hardware
- EPS 3.2 camera unit
- Black box, cabrio box, V2V unit
- Pedestrian unit, captain box, V2P unit
- Relay box
- Light tower and wireless light controller (WLT)
- PalletTrack unit V2
Software
- POS application
- SafeTrack application
- CloudConnect application (TLS-enabled server for remote access and updates)
- Third-party components listed in our Software Bill of Materials (SBOM)
3. How to report
You can reach our Product Security team through either channel below. Both are reviewed by a person.
- Email: security@essensium.com
- Web form: https://essensium.com/security-report/
Encryption: For sensitive details, please encrypt your report using our public PGP key: https://www.essensium.com/.well-known/security.asc
Languages: We handle reports in English and Dutch.
You do not need an account to report a vulnerability, and reports may be submitted anonymously.
4. What to include
The more of this you can give us, the faster we can act:
- Product name and version
- Hardware revision
- Software or firmware version
- Description of the vulnerability
- Impact — what an attacker could achieve
- Steps to reproduce, or a proof-of-concept
- Whether you have observed the issue being exploited
- Your preferred disclosure timeline
Please use our PGP key for anything sensitive.
5. What we commit to
Acknowledgement
- Within 24 hours for critical and high severity reports
- Within 72 hours for all other reports
Triage and verification We validate and reproduce the report, assign a severity score, and determine applicability across affected products using our SBOM and VEX data. Our process follows ISO/IEC 29147 and ISO/IEC 30111.
Remediation We remediate without undue delay. Speed scales with severity. Security fixes are developed on branches separable from feature development, so a fix never waits on a feature release.
Communication We update you at least every 14 days until the issue is resolved.
Testing We run regular static analysis, dynamic testing, dependency scanning and penetration testing across the products in scope.
6. Rules of engagement
To stay within the protections of Section 7, please:
- Only test against systems you own or are authorised to test. Do not test against other customers’ installations.
- Do not access, modify or exfiltrate data that is not yours. If you encounter personal data, stop and tell us.
- Do not degrade, disrupt or deny service to production systems, and do not attempt physical attacks on installed equipment.
- Do not use social engineering, phishing or physical intrusion against Essensium staff, customers or facilities.
- Give us reasonable time to remediate before disclosing publicly.
7. Safe harbour
Essensium will not pursue legal action against good-faith security research that stays within the scope of this policy, respects the rules of engagement above, and avoids privacy harm, service disruption and data exfiltration.
If you follow this policy in good faith and something goes wrong, tell us — we will work with you.
8. Coordinated disclosure and public advisories
Once a fix is available, we publish an advisory containing the description, affected products, impact, severity and remediation steps. We delay publication only in duly justified cases, and only until users have had a reasonable opportunity to apply the patch.
We credit reporters in our advisories unless you ask us not to.
9. Security updates
Security updates are signed and authenticated, are separable from feature updates, and are provided free of charge — except for tailor-made B2B products where different terms have been contractually agreed.
Every update is accompanied by an advisory describing the issue and the action required. For SafeTrack, updates are delivered through CloudConnect using secure remote system updates, automatically where applicable.
10. Support period
Vulnerability handling runs for the full support period of the product.
For SafeTrack system v3.2, the support period is 5 years from the date the product was placed on the EU market. The support-period end date is stated in the product information accompanying the product.
11. Governance
This policy is owned by the Essensium Product Security Team. It is reviewed annually, and after any significant security incident.
Version 1.0 — last reviewed 09/09/2026

