Coordinated Vulnerability Disclosure (CVD) Policy
Use this page to report a suspected product cybersecurity vulnerability affecting an MCm product. MC Monitoring SA (MCm) values reports from customers, partners, security researchers, and other persons who identify a potential product-security vulnerability. This CVD Policy explains how to report a vulnerability and how MCm coordinates assessment, remediation, communication, and disclosure.
Scope
This policy covers suspected cybersecurity vulnerabilities affecting MCm products with digital elements, including related firmware, software, update mechanisms, manager applications, configurations, and product-related third-party components.
Reports concerning corporate IT systems, websites, services, privacy matters, physical security, fraud, or general product-quality issues may be redirected to the appropriate MCm contact or process.
Reporting Channels
The primary and preferred reporting channel is the secure HTTPS Product Claim Process. Include CYBER in the Summary field so that the report is prioritised and routed for security review.
Only if the Product Claim Process is unavailable, use the fallback security address:
cyber.security(at)mc-monitoring.com
Standard email is not considered a secure channel. PGP encryption is not required, but passwords, credentials, exploit code, personal data, or other sensitive material shall not be sent by email. The fallback email should contain only the minimum information needed for MCm to establish contact and arrange an appropriate secure exchange.
Information To Provide
Provide as much of the following information as is available:
- affected product or product family.
- model, version, firmware, software, hardware variant, or serial number.
- vulnerability description and potential impact.
- reproduction steps, proof-of-concept description, logs, screenshots, or other supporting evidence.
- known or suspected exploitation.
- regulatory assessment and reporting where applicable.
- closure and evidence retention.
A report may be submitted even when some information is unavailable. Do not delay reporting solely to complete every field.
What To Expect
MCm aims to acknowledge receipt within seven calendar days when valid reporter contact information is available.
After acknowledgement, MCm aims to complete the initial triage and provide an initial assessment response within 14 calendar days. Critical, actively exploited, or otherwise urgent reports are prioritised and may receive a faster response. The initial response may confirm the affected scope, request additional information, or explain the next investigation or coordination steps; it does not necessarily include a final remediation decision.
While the case remains open, MCm aims to provide the reporter with a status update at least every 30 calendar days, unless a different communication schedule has been agreed with the reporter. Updates may be limited to information that can be shared safely and lawfully while investigation, remediation, supplier coordination, regulatory reporting, or an agreed embargo is in progress.
Depending on the nature of the report, the vulnerability-handling process may include
- acknowledgement and registration.
- assessment and triage.
- technical investigation and affected-version analysis.
- remediation or mitigation planning and validation.
- customer communication and coordinated disclosure where required.
- regulatory assessment and reporting where applicable and closure and evidence retention.
Final resolution timing depends on severity, exploitability, product impact, affected customers, technical complexity, update constraints, supplier coordination, and regulatory requirements.
The 24-hour CRA Early Warning deadline is a regulatory reporting deadline that may apply after MCm becomes aware of an actively exploited vulnerability or severe product-security incident. It is separate from the acknowledgement provided to the reporter.
Coordinated Disclosure And Embargo
To reduce risk to users, MCm asks reporters to keep vulnerability details confidential while MCm investigates and prepares corrective or mitigating measures. MCm and the reporter should seek to agree on a reasonable disclosure date or embargo period based on severity, active exploitation, remediation availability, customer deployment constraints, supplier coordination, and applicable law.
MCm may request an extension when additional time is reasonably needed to protect users. A reporter may request an earlier date or explain why continued embargo is no longer appropriate. Regulatory reporting, urgent user protection, or another legal obligation may require MCm to communicate before the agreed public-disclosure date.
Public disclosure should avoid exploit-enabling details until affected users have had a reasonable opportunity to apply available remediation or mitigation.
Reporter Recognition
At the reporter's request, MCm may recognise the reporter in a public advisory or release note when the report has been validated, the proposed wording is accepted by the reporter, and recognition does not create a security, privacy, legal, contractual, or operational risk. Anonymous reporting and requests not to be named are respected where practicable and legally permitted.
Good-Faith Reporting
MCm supports good-faith security research conducted in accordance with this policy by reporters who act responsibly, avoid privacy violations and service disruption, do not access or modify data beyond what is necessary to demonstrate the issue, and allow MCm reasonable time to investigate and protect affected users before public disclosure.
This statement does not authorise testing of customer systems, unsafe testing of operational or industrial equipment, social engineering, denial of service, physical intrusion, privacy violations, or unlawful activity.
Regulatory And User Notifications
MCm assesses reports against applicable legal obligations, including CRA Article 14. Where required, MCm may notify the coordinating CSIRT, ENISA, affected users, customers, partners, suppliers, or other competent parties. Such notifications may occur independently of the reporter acknowledgement and coordinated public-disclosure timeline.
Last updated: 2 September 2026