Skip to main content

Zgłaszanie podatności

Vulnerability reporting — Flowair products

Contact

"Contact — Flowair product security"
We accept reports at security@flowair.com

We handle inquiries in Polish and English.


Flowair Sp. z o.o., ul. Chwaszczyńska 135, 81-571 Gdynia. General phone: +48 58 627 57 20.

CRA Notice:
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers of products with digital elements to provide a channel for receiving vulnerability reports and to manage them in a coordinated manner. By sending a report to security@flowair.com, you help us resolve the issue before it can be exploited.
 


This policy applies to Flowair products featuring digital components, firmware, and software. Included:

  • Flowair product firmware and software—update panels, deployment, and update mechanisms.
  • Local network services—communication and industrial interfaces—where the vulnerability affects Flowair devices. 
  • Integration with cloud services—where the issue arises from using a Flowair product with third-party services; we accept the report and, if necessary, escalate it to the provider. 
  • Flowair integration tools available within product lines.


    Out of scope: general Flowair IT infrastructure unrelated to products, and vulnerabilities solely on the provider's side (please direct these to the provider).

 

  • Title and description of the issue — potential impact on confidentiality, integrity, and availability
  • Product name and firmware/software version (if known) 
  • Reproduction steps (PoC) — do not test on production systems without the owner's consent. 
  • Affected component or interface
  • Preferred timeframe for coordinated disclosure (if applicable)
  • Contact details for acknowledgment of receipt and further correspondence.
     
  • Handling process and our commitments
  • Acknowledgment of receipt — we confirm receipt of the report without undue delay 
  • Initial assessment — analysis of the impact on the product and the severity of the vulnerability; we ask follow-up questions if necessary 
  • Remediation plan — development of a fix or temporary countermeasures; we inform the reporter of the planned course of action 
  • Disclosure coordination — we agree on a date for public disclosure; we do not publish details before the fix or countermeasures are made available
  • Recognition — upon the reporter's request, the possibility of being listed in the Flowair security bulletin

If the report concerns solely the infrastructure of a third-party provider, please submit it in accordance with that provider's vulnerability disclosure policy. Flowair documents the impact of third-party services on the security of its products in the technical documentation (Technical File / CRA Annex I). If in doubt, please email security@flowair.com - we will help you identify the appropriate recipient.

 

  • Act in good faith—do not exploit vulnerabilities beyond what is necessary to demonstrate their impact.
  • Do not violate end-user privacy (minimize personal data in your report).
  • Do not demand payment for the report or threaten disclosure before contacting Flowair.
  • Flowair commits to acting in good faith toward researchers who adhere to the above guidelines.
     
Product support and versions


In accordance with CRA requirements (Art. 13(8)), Flowair provides security support for its products for the duration specified in the respective product support policy. Current policies, firmware versions, and published security updates are available on the product webpages and through Flowair support channels. For inquiries regarding support periods or current versions, please contact security@flowair.com. CE Declarations of Conformity are available in the product documentation or upon request at info@flowair.pl.