Dukosi PSIRT
Dukosi takes a proactive approach to product security, recognising that no product can be fully secure in a continually evolving product security landscape. The Dukosi Product Security Incident Response Team (PSIRT) is committed to rapidly addressing potential security vulnerabilities affecting Dukosi’s products through the channels provided below — accepting and responding to vulnerability reports, assessing impact and severity, and providing our customers with clear guidance on mitigations and solutions where applicable.
How to Report a Potential Security Vulnerability
To report a potential security vulnerability, please contact Dukosi PSIRT at psirt@dukosi.com
To allow Dukosi to process the potential vulnerability, you should provide the following information:
- A detailed description of the vulnerability
- A detailed description of potential exploits resulting from vulnerability
- The date when the vulnerability was detected
- Details about how it was discovered
- The full hardware setup and firmware revision(s) used and any detail necessary to replicate and confirm the vulnerability.
- Any public information already published (CVE, academic paper publication, etc.)
- Your contact information
- Name / Alias
- Organization & Department name (if applicable)
- Email Address (required for further contact)
- Phone number including country code (if applicable)
We aim to reply promptly, however insufficient information may prevent Dukosi from processing the report. All received information and exchanges will be conducted in English and are subject to our privacy policy. We recommend encrypting sensitive reports using our public key.
Fingerprint: 0C70 E276 1419 67C6 45D9 9AFA 4D52 C45A D2DB F1E3
Vulnerability Handling Process
- Receive — We will acknowledge your report
- Assess — We will confirm the report validity and determine severity
- Remediate — We will develop and verify a fix or mitigation
- Disclose & Report — We will coordinate disclosure with you, and will make arrangements to meet any applicable regulatory reporting obligations. Dukosi’s approach to coordinated disclosure follows the principles set out in the CERT® Guide to Coordinated Vulnerability Disclosure.
EU Cyber Resilience Act (CRA) Compliance Statement
Dukosi is committed to compliance with the EU Cyber Resilience Act (Regulation (EU) 2024/2847). We are preparing our vulnerability handling and incident reporting processes to meet the Act’s requirements ahead of the September 2026 reporting obligations, with full compliance targeted by the December 2027 deadline. Dukosi is aligning its vulnerability handling processes with the EN 40000-1-3 standard as it progresses through CEN standardisation in support of the EU Cyber Resilience Act.
Dukosi applies a systematic security approach across each product’s lifecycle, including product classification support, conformity assessment guidance, vulnerability handling, and ongoing maintenance. This includes coordinated vulnerability disclosure practices aligned with recognised standards, integration of security into development processes, monitoring of potential vulnerabilities, and provision of security updates and support throughout defined product support periods where applicable.
Out of Scope Statement
This policy covers vulnerabilities in Dukosi products and product deliverables. It does not cover vulnerabilities in Dukosi’s IT infrastructure or website, which should be reported to support@dukosi.com, or vulnerabilities in third-components where Dukosi has no product responsibility.
Further Information
Security Advisories
No current advisories at this time.