As part of DEIF’s responsible security practice and in preparation for applicable legal obligations, DEIF maintains a formal process for receiving and handling reports of potential vulnerabilities in DEIF products.
How to report a vulnerability
Email: security@deif.com
What to include:
DEIF product name, model and software or firmware version.
Description of the potential vulnerability and the conditions under which it can be triggered.
Evidence or proof of concept, if available.
Contact details for follow-up.
What to expect from DEIF:
Acknowledgement within 3 business days.
Assessment and triage within 10 business days.
Regular status updates through to resolution.
Credit in DEIF security advisories, if requested and appropriate.
Our commitment
DEIF will not take legal action against researchers who report vulnerabilities in good faith in accordance with these guidelines. We ask that you allow us reasonable time to investigate and address issues before public disclosure.
Consistent with CRA Article 14 requirements, DEIF will report actively exploited vulnerabilities to ENISA and the relevant national CSIRT via the CRA Single Reporting Platform within the statutory deadlines: early warning within 24 hours, full notification within 72 hours, and final report within 14 days of a corrective measure being available.
Read more about cybersecurity in DEIF
-
Contact us to discuss your options
- 90 years of energy pioneering
- Manufactured at the highest standards
- Superior quality
- Unmatched service and support
- Made in Denmark