Coordinated Vulnerability Disclosure policy
1. Introduction
SYMETRIE is committed to the security of our products and the protection of our customers. We value the security research community and welcome the responsible disclosure of vulnerabilities.
This Coordinated Vulnerability Disclosure (CVD) policy is implemented by SYMETRIE as a manufacturer of digital products, aligned with the principles of Regulation (EU) 2024/2487 (Cyber Resilience Act – CRA), Annex I, Part II. It is part of our vulnerability management process, which aims to identify, fix, and communicate vulnerabilities affecting our products throughout their lifecycle.
2. Scope
This policy applies to:
- all products manufactured by SYMETRIE
- software and firmware embedded in our products, developed by SYMETRIE
- web content at *.symetrie.fr
- all applications published by SYMETRIE
Vulnerabilities affecting only third-party products, services, or platforms not integrated into our products must be reported directly to their manufacturer or supplier, in accordance with their own disclosure policy.
As a distributor, SYMETRIE does not manage vulnerability management for optional computers. In the event of a security breach on this hardware, please refer to the manufacturer’s vulnerability management policy.
Please note that certain components of our products, such as the operating system, are provided by third-party vendors. While SYMETRIE monitors and integrates relevant security updates from these vendors, the remediation of vulnerabilities affecting these components may depend on the availability of fixes from the original suppliers. SYMETRIE commits to addressing such issues through updates, mitigations, or other appropriate measures where feasible, subject to vendor timeline.
3. How to report
Email our security team: security@symetrie.fr
Security.txt file: https://symetrie.fr/security.txt
To facilitate the processing of your report, we invite you to provide the following information
- affected product(s) and version(s)
- clear description of the vulnerability
- detailed steps to reproduce the issue
- assessment of potential impact (confidentiality, integrity, availability)
- your suggested fix (optional)
- your contact information for follow-up
A complete report facilitates our analysis and speeds up resolution.
4. Internal vulnerability management process
All reported vulnerabilities are handled as part of our vulnerability management process, which is consistent with the CRA framework.
- each confirmed vulnerability is logged in our vulnerability management system.
- it is assessed using an impact matrix (confidentiality, integrity, availability) and, where possible, according to the CVSS standard.
- a remediation plan is implemented (patch, update, configuration, SBOM, etc.), prioritized based on severity and risks to users.
This process is documented and reviewed regularly as part of our cybersecurity and CRA compliance policy.
5. Our commitments
We strive to maintain a transparent and efficient workflow. Our typical timelines are as follows:
| Timeframe | Action |
| Within 5 business days | Acknowledgment of receipt of your report (depending on report volume) |
| Within 15 business days | Initial assessment and severity rating (subject to technical complexity) |
| Every 14 days | Status update provided until resolution |
| 90 days | Resolution target for high and critical vulnerabilities |
We may notify you of extensions to these timelines for complex vulnerabilities requiring coordinated fixes across multiple products or vendors, or for specific cases listed below.
6. Disclosure timeline
We follow a flexible 90-day disclosure framework:
- day 0: you report the vulnerability,
- days 1-5: we acknowledge the report and conduct an initial analysis,
- days 6–89: we work on the fix,
- day 90: Coordinated public disclosure, unless an extension is mutually agreed upon.
Extension protocol: If exceptional circumstances (such as major technical complexity, hardware vulnerabilities requiring supply chain coordination, or multi-vendor dependencies) prevent meeting the 90-day deadline, we commit to proactively engaging in discussion with the researcher prior to Day 90 to agree on a new disclosure date. Public disclosure will only be triggered if coordination fails or in the event of confirmed active exploitation posing a significant risk to users.
In such cases, SYMETRIE will engage in expedited coordination to assess the situation and determine appropriate mitigation and disclosure actions.
7. ENISA / CSIRT notification
When we determine that a vulnerability is being actively exploited and poses a significant risk to user security or safety, we notify ENISA (the European Union Agency for Cybersecurity) and national cybersecurity authorities (CSIRTs) in accordance with the deadlines set forth in the CRA. We commit to:
- notifying ENISA within 24 hours of confirming the exploitation,
- completing the detailed report within 72 hours,
- coordinating with national CSIRTs when appropriate.
8. Notice to users
Once a vulnerability has been resolved, we notify all affected customers via email without undue delay. This notice includes:
- a description of the vulnerability and its potential impact
- the affected products and versions
- the available update or patch
- instructions for updating or mitigating the issue
This information is also available upon request through our technical support. Security patches addressing identified security issues are provided free of charge during the applicable CRA support period, as required by applicable law. Other updates, upgrades, additional functionality and support services may be subject to applicable licensing fees and support contract terms.
9. Safe harbor
SYMETRIE commits to refraining from civil legal action regarding violations of our Terms of Service or specific computer abuse laws, to the extent permitted by applicable law, provided that the researcher strictly adheres to the boundaries defined below:
- act in good faith and comply with this policy
- refrain from accessing, modifying, or deleting user data
- do not disrupt our services or harm our customers
- report vulnerabilities promptly
- allow a reasonable period for remediation before disclosure
This safe harbor applies to potential violations of:
- computer abuse laws
- our terms of service
- data protection requirements (including incidental access during vulnerability research)
It does not cover malicious activities, service abuse, or intentional harm.
10. Outside the scope
The following are outside the scope of this policy:
- social engineering of employees or customers
- physical attacks on our facilities
- hacking that uses physical access to machines as an entry point
- denial-of-service attacks
- detections by automated scanners with no demonstrated impact
- issues in third-party services
Vulnerabilities affecting only third-party components not integrated into our products must be reported to the relevant manufacturer or supplier.