VAT is committed to the security and reliability of its products throughout their supported lifecycle. We welcome responsible reports from customers, security researchers, partners and other parties who believe they have identified a potential security vulnerability affecting a VAT product.

The VAT Product Security Incident Response Team (VAT PSIRT) coordinates the assessment and handling of reported product security issues.

What should be reported?

Please contact VAT PSIRT if you believe you have identified a security vulnerability affecting:

  • VAT Valve Controller
  • Firmware supplied by VAT

This channel is intended for product security vulnerabilities and product-related cybersecurity incidents.

For general product support, application questions, spare parts, repairs or commercial inquiries, please use the regular VAT support or contact channels.

Information to Include

Product Identification

  • VAT Product or Valve Series
  • Type of Controller
  • Ordering number
  • Fabrication or serial number
  • Firmware or software version
  • Communication interface, for example EtherCAT, Ethernet, RS232 or another fieldbus
  • Relevant hardware configuration or option boards

Vulnerability Details

  • Description of the suspected vulnerability
  • Observed or potential security impact
  • Steps required to reproduce the issue
  • Required access level or equipment
  • Whether the issue has been observed in an operational environment
  • Whether you have evidence that the vulnerability is already being exploited
  • Suggested mitigation or corrective action, if known

Supporting Information

  • Logs, traces or diagnostic output
  • Proof-of-concept files or commands
  • Relevant screenshots
  • Network captures
  • Your preferred contact details

Please do not send customer production data, personal data, credentials, cryptographic keys or other confidential information unless it is essential for the investigation and has been appropriately protected.

How to report a vulnerability

Please send your complete report directly to psirt@vatgroup.com, including your contact details, the affected product, a vulnerability summary and the technical description as well as the steps to reproduce the vulnerability.

What Happens after a Report?

VAT will:

  1. Register and review the report
  2. Assess whether it concerns a VAT product and whether sufficient information is available
  3. Determine the potential security impact and affected products or versions
  4. Coordinate investigation and corrective or mitigating actions with the relevant VAT teams
  5. Communicate relevant information to affected parties and competent authorities where legally required.

VAT may contact you for additional technical information. Reports will be handled according to their potential security impact and the information available.

Coordinated Disclosure

To help protect VAT customers and users, we ask reporters to:

  • provide VAT with a reasonable opportunity to investigate and address the issue before public disclosure
  • avoid accessing, modifying or deleting data that does not belong to them
  • avoid actions that could disrupt customer operations, production systems or safety-related functions
  • limit testing to the minimum necessary to demonstrate the issue
  • keep vulnerability details confidential while investigation and remediation are ongoing

VAT will seek to cooperate openly and professionally with reporters. Where appropriate, VAT will coordinate the timing and content of any public disclosure with the reporter and affected stakeholders.

Recognition

VAT may acknowledge reporters who have provided a valid and responsibly disclosed vulnerability, subject to the reporter’s consent and applicable confidentiality requirements.

VAT does not currently operate a public bug bounty program, and submission of a report does not create an entitlement to payment or compensation.

Privacy

VAT processes the personal and technical information submitted through this channel for the purpose of receiving, investigating and responding to product security reports and complying with applicable legal obligations

Please refer to the VAT Privacy Policy for information about the processing of personal data and the exercise of data-protection rights.