PSIRT
RonTech Product Security Incident Response Team
RonTech takes the security of its products seriously. This page describes how you can report a security vulnerability and how we handle security incidents.
RonTech complies with the reporting obligations for security incidents under the EU Cyber Resilience Act (CRA), Article 14.
Contact RonTech PSIRT
E-Mail: psirt@rontech.ch
Response time
We confirm receipt of a report within 3 business days and inform you about the further process.
What you can report
Security vulnerabilities in RonTech products (controllers, software, remote access solutions).
Suspicion of an active security incident.
Responsible Disclosure
We kindly ask you to:
Not disclose vulnerabilities publicly before a fix is available.
Not conduct tests or attacks on productive customer systems.
Provide sufficient information for reproduction (affected product, version, description).
Our process upon receiving a report
We confirm receipt of your report.
We analyze the vulnerability and assess its severity.
In the case of actively exploited vulnerabilities or serious incidents, we inform the relevant authorities in accordance with the CRA.
We develop a patch, update, or recommended action.
Affected customers receive the relevant information and recommended actions from us.