Serwis Pojazdów Szynowych, Rolling Stock Service
  1. pl
  2. en

Product Security and Vulnerability Disclosure (CRA / CVD)

Language: Polski | English

The security of our products with digital elements and the protection of our customers' data are our highest priorities. In accordance with the EU Cyber Resilience Act (CRA), we have implemented a formal Coordinated Vulnerability Disclosure (CVD) process.


1. Single Point of Contact (SPOC / PSIRT)

Please direct any reports concerning potential vulnerabilities, exploits, or security flaws in our products, software, or digital services directly to our dedicated response team:


2. Safe Harbor Policy (Good Faith Research)

We value collaboration with the security research community. If you conduct research in good faith and adhere to the guidelines below, we commit to:

  • Not initiating legal action or filing complaints with law enforcement in connection with your research.
  • Collaborating transparently to understand and resolve the issue in the shortest possible timeframe.
  • Acknowledging your contribution in resolving the flaw (e.g., in a Security Advisory), provided you consent to attribution.

Researcher requirements:

  • Do not violate user privacy or the confidentiality of corporate data.
  • Do not destroy, modify, or exfiltrate data.
  • Avoid actions that could disrupt service continuity (e.g., Denial of Service – DoS/DDoS attacks).
  • Do not demand financial compensation or ransoms in exchange for withholding disclosure.
  • Grant us reasonable time to remediate the vulnerability before public disclosure (default standard: 90 days).

3. Out-of-Scope Submissions

Under our CRA CVD process, we do not assess submissions lacking practical security impact, including:

  • Missing HTTP security headers (e.g., CSP, HSTS, X-Frame-Options), unless directly tied to an exploitable flaw.
  • SPF/DKIM/DMARC configuration quirks without practical account compromise impact.
  • Social engineering (phishing, vishing) directed at employees.
  • Physical attacks against facilities or hardware infrastructure.
  • Automated scanner outputs without practical validation and an operational Proof of Concept (PoC).

4. Response Timelines & SLA

Our PSIRT commits to the following response timeline:

  • Within 72 hours: Formal receipt acknowledgment of the vulnerability report.
  • Within 7 calendar days: Initial triage, severity assessment (CVSS), and remediation action plan.
  • Standard 90-day window: Development, testing, and release of a security patch or mitigation, followed by coordinated disclosure. In justified cases, this timeframe may be modified by mutual agreement.

+48 52 326 70 10

sps@serwis-mieczkowski.pl

SPS sp. z o.o. sp. k  © 2024