Security

Report a vulnerability or security incident

ACRIOS Systems takes the security of our products and services seriously. If you have found a vulnerability, or want to report a security incident related to our products, please use the link below. No account or registration required.

Photo is illustrative only
i
1 480 000+
Connected meters
10 000
Devices within our largest project
25+
Developers
9+
Years on the market
€ 2.5M+
Annual turnover

What to include in your report

  • which product is affected, including firmware or hardware version
  • what you found and what impact it may have
  • how to reproduce the issue
  • how to reach you, if you would like to be kept informed

What happens next

1. We acknowledge receipt within 3 working days.

2. We verify the finding and assess its severity.

3. We inform you of the outcome and our remediation plan, where contact details are available.

4. We follow coordinated vulnerability disclosure principles. Technical details are published only once a fix or mitigation is available.

Full details of principles are available here

Protection for reporters

If you act in good faith and in line with our policy, we will not pursue legal action against you. We will not disclose your identity without your consent. If you wish, we will credit you in our acknowledgements.

Out of scope

Please do not use testing methods that could disrupt operations or affect third-party data: denial of service (DoS) attacks, physical attacks, social engineering against our employees or customers, and testing of systems we do not operate. The full scope is set out in the policy.

Fixed vulnerabilities

Once a fix is available, we publish details on our security advisories page.

Want to stay fully anonymous?

You may also report through your national CSIRT, which can forward the report to us without disclosing your identity.