• Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Version: 1.0
Effective date: 11.09.2026
productsecurity@wetrok.com

Report a Vulnerability Now:

Go to the form

Purpose

Wetrok takes the security of its products very seriously. This policy describes how security researchers, customers, and other third parties can responsibly report potential vulnerabilities in Wetrok products and what they can expect from us in return.

Scope

This policy applies to all products with digital elements manufactured or distributed by Wetrok, including machines, control systems, software, connected devices, and associated digital components.

How to Report a Vulnerability

Preferred reporting channels, in order of preference:
  1. Web form: Product Security

  2. Email: productsecurity@wetrok.com

Please provide the following information where possible:
  • Product name and version (software/firmware/hardware)

  • Detailed description of the vulnerability

  • Steps to reproduce the issue (Proof of Concept)

  • Estimated impact

  • Your contact details (optional, but helpful if we need to follow up)

Our Commitments

  • We generally acknowledge receipt of a report within 48 business hours.

  • We treat all reports confidentially.

  • We assess and prioritise each report and keep you informed of our progress, provided you have supplied contact details.

  • We address confirmed vulnerabilities as quickly as reasonably possible and publish Security Advisories where appropriate.

  • At your request, and with your consent, we may acknowledge your contribution publicly by name or pseudonym in our Hall of Fame.

Expected Conduct of Reporters

  • Report vulnerabilities responsibly and avoid unnecessarily affecting the availability, integrity, or confidentiality of systems or data.

  • Do not conduct testing in production customer environments without explicit authorisation.

  • Do not publicly disclose the vulnerability before we have released a remediation or agreed to disclosure, typically following prior coordination.

  • Act in good faith.

Safe Harbor

Wetrok will not pursue legal action against individuals who report vulnerabilities in good faith and in accordance with this policy, provided that their activities do not cause unnecessary harm.

Changes

Wetrok reserves the right to update this policy. The current version is always available at Vulnerability Disclosure Policy.

Contact

Wetrok AG
Product Security
Steinackerstrasse 62
CH-8302 Kloten
E-Mail: productsecurity@wetrok.com

Report a Vulnerability Now:

Go to the form