TECHSYS

Coordinated Vulnerability Disclosure (CVD) Policy

Scope

This policy applies to products and software developed and marketed by TECHSYS – HW a SW, a.s. It does not apply to third-party systems into which our products are integrated.

How to Report a Vulnerability

Please send your report to psirt@techsys.cz. Sensitive information should be encrypted using the PGP key published at https://techsys.cz/well-known/psirt-pgp-key.txt. We accept reports in Czech and English.

Please include the affected product and version, a description of the vulnerability with steps to reproduce it, an assessment of its potential impact, and, where applicable, proof-of-concept code. Please do not include personal data of third parties or data obtained from systems belonging to others.

Our Commitment

Safe Harbor

We will not pursue legal action against security researchers who act in good faith and within the scope of this policy. To qualify for this protection, researchers must refrain from:

Acknowledgements

With the researcher's consent, we will acknowledge them by name in the relevant vulnerability advisory. We do not currently offer financial rewards.

Effective date: 11 September 2026 | Version: 1.1 | Contact: psirt@techsys.cz

Copyright © TECHSYS - HW a SW, a.s. Všechna práva vyhrazena