Dukosi PSIRT

Dukosi takes a proactive approach to product security, recognising that no product can be fully secure in a continually evolving product security landscape. The Dukosi Product Security Incident Response Team (PSIRT) is committed to rapidly addressing potential security vulnerabilities affecting Dukosi’s products through the channels provided below — accepting and responding to vulnerability reports, assessing impact and severity, and providing our customers with clear guidance on mitigations and solutions where applicable.

How to Report a Potential Security Vulnerability

To report a potential security vulnerability, please contact Dukosi PSIRT at psirt@dukosi.com

To allow Dukosi to process the potential vulnerability, you should provide the following information:

We aim to reply promptly, however insufficient information may prevent Dukosi from processing the report. All received information and exchanges will be conducted in English and are subject to our privacy policy. We recommend encrypting sensitive reports using our public key.

Fingerprint: 0C70 E276 1419 67C6 45D9 9AFA 4D52 C45A D2DB F1E3

Download public key (.asc)

Vulnerability Handling Process

  1. Receive — We will acknowledge your report
  2. Assess — We will confirm the report validity and determine severity
  3. Remediate — We will develop and verify a fix or mitigation
  4. Disclose & Report — We will coordinate disclosure with you, and will make arrangements to meet any applicable regulatory reporting obligations. Dukosi’s approach to coordinated disclosure follows the principles set out in the CERT® Guide to Coordinated Vulnerability Disclosure.

EU Cyber Resilience Act (CRA) Compliance Statement

Dukosi is committed to compliance with the EU Cyber Resilience Act (Regulation (EU) 2024/2847). We are preparing our vulnerability handling and incident reporting processes to meet the Act’s requirements ahead of the September 2026 reporting obligations, with full compliance targeted by the December 2027 deadline. Dukosi is aligning its vulnerability handling processes with the EN 40000-1-3 standard as it progresses through CEN standardisation in support of the EU Cyber Resilience Act.

Dukosi applies a systematic security approach across each product’s lifecycle, including product classification support, conformity assessment guidance, vulnerability handling, and ongoing maintenance. This includes coordinated vulnerability disclosure practices aligned with recognised standards, integration of security into development processes, monitoring of potential vulnerabilities, and provision of security updates and support throughout defined product support periods where applicable.

Out of Scope Statement

This policy covers vulnerabilities in Dukosi products and product deliverables. It does not cover vulnerabilities in Dukosi’s IT infrastructure or website, which should be reported to support@dukosi.com, or vulnerabilities in third-components where Dukosi has no product responsibility.

Further Information

Security Advisories

No current advisories at this time.

Vulnerability Disclosure Policy (PDF) (opens in a new tab/window)
Back to top