You are in: Home Security Vulnerability Reporting

Security Vulnerability Reporting

Security Vulnerability Reporting

Use this page to report potential security vulnerabilities identified in Normagrup products, firmware or software.

The security of our products and solutions is a fundamental part of our commitment to quality, innovation and the protection of our customers and users. We therefore value the collaboration of researchers, professionals and users who help us identify potential vulnerabilities and maintain a high level of security.

Important: this page is intended exclusively for reporting potential vulnerabilities related to Normagrup products, firmware and associated software.

If you wish to report a vulnerability related to our website, applications or corporate systems, you can contact us exclusively by email at security@normagrup.com.

Vulnerability Disclosure Policy

At Normagrup, we work to ensure the security of our technological solutions and to protect the information and privacy of our users.

We recognise the value of collaboration with external security researchers and professionals who contribute to identifying potential vulnerabilities. This policy establishes guidelines for conducting such research responsibly and reporting any issues identified to us.

If you identify a potential vulnerability in any of our products or solutions, we ask that you report it to us before making it public, allowing us to analyse it and, where appropriate, take the necessary measures to resolve it.

Authorisation

If your research is conducted in good faith and in accordance with the guidelines set out in this policy, Normagrup will handle your report responsibly and will work with the person who submitted it to understand, assess and, where appropriate, resolve the identified vulnerability.

Research guidelines

We consider responsible research to include activities in which you:


  • Notify us as soon as possible after discovering an actual or potential security issue.
  • Avoid any action that could result in a data breach, affect other users, disrupt our systems or services, or destroy, modify or manipulate information.
  • Use only the techniques necessary to confirm the existence and scope of the potential vulnerability.
  • Do not use a vulnerability to access, copy, modify or extract information without authorisation.
  • Do not attempt to maintain persistent access to our products, systems or infrastructure, or to access other related systems.


If, during your research, you accidentally access personal data, confidential information, financial information, intellectual property or any other sensitive content, you must immediately stop testing, notify us as soon as possible and refrain from storing, using or disclosing such information to third parties.

Scope

This policy applies to:

  • Products marketed under Normagrup brands.
  • Firmware associated with these products.
  • Software and digital tools directly related to their operation, configuration or maintenance.


Any other system or infrastructure is outside the scope of this policy unless expressly stated otherwise by Normagrup.

Reporting a vulnerability

The information received will primarily be used to analyse, mitigate and resolve potential security vulnerabilities.

If the reported vulnerability could affect third parties — such as suppliers, partners, distributors or customers — Normagrup may share the information strictly necessary with the parties involved to facilitate its analysis and resolution.

You can report a potential vulnerability via:


security@normagrup.com


Reports may be submitted anonymously, although providing contact details will allow us to request additional information and keep you informed about the progress of our analysis.

Recommended information

To help us properly analyse and prioritise the issue, we recommend that your report:

  • Is preferably written in English or Spanish.
  • Includes a clear description of the vulnerability.
  • Indicates the reference or model of the affected product.
  • Includes the manufacturing date, where relevant.
  • Indicates the version of the affected firmware or software, where applicable.
  • Explains where and how the vulnerability was identified and what its potential impact may be.
  • Includes the steps required to reproduce it.
  • Includes, where useful, screenshots, logs, videos or proof-of-concept materials to facilitate our analysis.

Our response

When you provide your contact details, we will endeavour to maintain open and transparent communication throughout the analysis process.

After receiving a report:

  • We will acknowledge receipt within a maximum of 5 working days.
  • Our team will analyse the information provided and may contact you to request additional details.
  • Where necessary, we will keep the reporter informed about the progress of the analysis and any measures taken.
  • Once the vulnerability has been assessed, we will work to implement the appropriate mitigation or corrective measures.


We appreciate your collaboration in helping us maintain the security and reliability of Normagrup products and solutions.


Configure cookies