PRODUCT SECURITY
If you identify a potential security vulnerability in a Jenny Science product, please report it to us confidentially. Your information helps us protect our products and customers as effectively as possible.
Report a Security Vulnerability
Please send information about potential product security vulnerabilities or security-related incidents to our central Product Security contact.
Affected Products
The Product Security contact is intended in particular for the following products:
- XENAX® Xvi servo controllers
- INTAX® Tx linear motor axes with integrated servo controller
What Information Do We Need?
Please provide the following information, where available:
- Product name and variant
- Hardware, firmware, and software version
- Description of the observed security vulnerability or incident
- Steps to reproduce the issue
- Affected interface or function
- Logs, screenshots, or other technical information
- Contact details for follow-up questions
How We Handle Your Report
- Receipt
We register your report and confirm receipt. - Analysis
We review the report and assess potential impacts and affected product versions. - Measures
If required, we provide protective measures, fixes, or security updates.
Coordinated Vulnerability Disclosure (CVD)
Jenny Science follows a coordinated disclosure process for reported security vulnerabilities (Coordinated Vulnerability Disclosure, CVD).
The aim is to assess potential vulnerabilities confidentially, prepare appropriate protective or corrective measures, and coordinate any potential disclosure with the parties involved.
We ask security researchers, customers, integrators, and other reporters not to publicly disclose technical details of a potential security vulnerability while our analysis is ongoing and appropriate protective or corrective measures are not yet available.
Confirmed security vulnerabilities are assessed and handled as part of our Product Security process. If required, we inform affected customers and provide appropriate protective measures, fixes, or security updates.
A report submitted to security@jennyscience.ch is considered an entry into our CVD process. We confirm receipt and contact the reporter if additional technical information is required.