Vulnerability Disclosure Policy
This policy describes how you can report a potential security vulnerability to us and what you can expect from us when you do so.
Scope
This policy applies to all products, systems, and digital services of DOLI Elektronik GmbH, including our EDCi control and regulation systems, expansion modules, software, as well as our website and online services.
Third-party systems are not covered by this policy, even if they are connected to DOLI products or carry DOLI trademarks. If you are unsure whether a finding falls within the scope of this policy, please report it to us anyway—we will assess it together with you.
How to Report a Vulnerability
Have you discovered a potential security vulnerability? Contact us at security(at)doli.de.
To help us process your report quickly, please provide the following information where possible:
- Affected product, model, and version number
- A description of the vulnerability
- The steps required to reproduce the vulnerability
- The potential impact, from your perspective
- If applicable, a CVSS score or classification (e.g., buffer overflow, unauthorized access)
Your contact details are optional. If you provide them, we can contact you if we have any questions and keep you informed about the progress of our investigation.
What You Can Expect from Us
- Confidentiality. We treat every report as confidential, regardless of whether you are already a customer of ours.
- Prompt acknowledgment of receipt.We will acknowledge receipt of your report within a few business days.
- An honest assessment.We carefully assess every report, evaluate the associated risk, and keep you informed about the progress.
- No legal action for good-faith security research. If you comply with this policy, we will not take legal action against you or notify law enforcement authorities in connection with your report.
Rules for Your Investigation
To ensure that we can classify your report as good-faith security research, we ask that you:
- Only test devices or systems that you own or for which you have explicit permission.
- Do not access, modify, or delete third-party data.
- Do not carry out attacks that could disrupt the operation of devices, systems, facilities, or services (e.g., denial-of-service attacks).
- To allow us sufficient time to review and remediate the issue prior to any public disclosure (see below)
Disclosure and Remediation
We address confirmed vulnerabilities in accordance with the principle of Coordinated Vulnerability Disclosure: We work on a solution and only publish information once a mitigation measure or patch is available. If necessary, we inform affected users in advance about the risks and recommended interim measures.
We kindly ask that you allow us a reasonable amount of time to address the reported vulnerability before publishing any details about it. We will agree on the exact timeframe with you on a case-by-case basis.
Acknowledgement
Upon request, we will credit you as the discoverer in our publication once the vulnerability has been resolved. If you prefer to remain anonymous, we will of course respect your decision.
Contact
Email:security(at)doli.de
DOLI Elektronik GmbH Rudolf-Diesel-Str. 3 72525 Münsingen
As of: September 16, 2026