Vulnerability Disclosure Policy (Coordinated Vulnerability Disclosure)

In compliance with the principles and obligations established by the European Union’s Cyber Resilience Act (CRA – Regulation EU 2024/2847), Soltronic is committed to ensuring the highest levels of security, reliability, and resilience across our products, hardware/software systems, and digital services throughout their lifecycle.

We recognize the critical importance of collaborating with our customers, users, security researchers, and the broader cybersecurity community to identify and resolve potential vulnerabilities in a timely manner.


1. Dedicated Contact Channel

To report security issues, software vulnerabilities, firmware bugs, or suspicious behavior related to Soltronic products or services, our official and dedicated channel is:

📧 Security Email: cybersecurity@soltronic.it

Note: This email address is strictly monitored for cybersecurity vulnerabilities only. For routine technical support or commercial inquiries, please use our standard support channels.

2. Scope

This policy applies to:

  • Hardware products and devices with digital elements (firmware, electronic boards, IoT) developed or distributed by Soltronic.
  • Software applications, web portals, and APIs owned or managed by Soltronic (including the domain soltronic.it).
  • Cloud services and connected infrastructures linked to Soltronic products.

3. What to Include in Your Report

To help us verify and process your report efficiently, please include as much detail as possible:

  • Issue Description: Type of vulnerability or security flaw identified.
  • Affected Products/Services: Model, firmware/software version, product code, or URL involved.
  • Reproduction Steps (Proof of Concept): Detailed step-by-step instructions to safely reproduce the issue.
  • Estimated Impact: Your assessment of potential risks to systems or data confidentiality.

4. Our Commitment & Response Timeline

We handle all received reports with high priority according to the following guidelines:

  • Acknowledgement: Receipt of your report will be acknowledged within 24–48 business hours.
  • Initial Assessment: Preliminary evaluation and request for additional details (if needed) within 5 business days.
  • Regular Updates: We will keep you informed about the progress of remediation and resolution activities.
  • Resolution & Patching: We strive to release security updates or fixes as quickly as possible based on severity and risk level.

5. Coordinated Vulnerability Disclosure Principles

We kindly ask all reporters to adhere to the following ethical guidelines (*Responsible Disclosure*):

  • Confidentiality: Keep vulnerability details confidential and refrain from public disclosure until Soltronic has developed and deployed an official fix or patch.
  • No Damage or Abuse: Do not exploit vulnerabilities to access, modify, or delete user data, disrupt services, or damage physical equipment.
  • Safe Testing: Perform tests only on devices you own or have explicit authorization to test. Avoid Denial of Service (DoS/DDoS) attacks or Social Engineering/Phishing techniques.
  • Good Faith: Always act in good faith and in compliance with applicable data protection legislation (GDPR).

6. Encrypted Communication (PGP)

For submitting highly sensitive technical details, we encourage encrypting your communication using our public PGP key.

Our PGP key can be located via our standardized security text file at: https://www.soltronic.it/.well-known/security.txt


Last updated: September 2026 — This page has been prepared in compliance with cybersecurity regulations and vulnerability management standards set forth by the Cyber Resilience Act (CRA).

IT IS IMPORTANT TO CAREFULLY CONSIDER THE SPECIFIC REQUIREMENTS OF THE USE CASE BEFORE IMPLEMENTING AN RFID SYSTEM, TO ENSURE THE BEST RESULT.

Request a consultation

CASE STUDIES

PHARMACEUTICAL INDUSTRY

How can you verify and track the serial numbers of all components used in operating room equipment?

Read

MEDICAL APPLICATION

How can you prevent miniaturized tools from accidentally ending up in product packaging?

Read

EYEWEAR MANUFACTURER

How can you quickly organize production batches with different processing characteristics?

Read

CONTACT US FOR A CONSULTATION

Fill out the form to get more information or request a consultation.

    * Mandatory fields

    Soltronic Srl | Cap. soc. 20.000,00 € i.v. | Numero REA UD-369822 | P.IVA 03120310309 | SDI T04ZHR3