Ergosoft – Coordinate Vulnerability Disclosure (CVD)
Version 1.0 · Effective June 2026
Purpose
Ergosoft takes the security of Ergosoft RIP seriously and welcomes reports of suspected vulnerabilities from the security community. This policy explains how to report an issue, what to expect from us, and how to investigate our software safely and in good faith.
Scope
In scope: Ergosoft RIP – all currently supported versions.
Out of scope: third-party software bundled with Ergosoft RIP (please report these to the upstream vendor); social engineering of Ergosoft staff; physical attacks; and denial-of-service testing. Reports about known vulnerabilities in third-party components, or raw scanner output without a demonstrated Ergosoft RIP-specific impact, are handled through normal Ergosoft support rather than this channel.
How to report
Send your report to security@ergosoft.net and include:
- Affected Ergosoft RIP version(s) and operating system.
- A clear description of the issue and its potential impact.
- Steps to reproduce, with proof-of-concept (PoC) code or files where helpful.
- Whether and when you intend to publish your findings.
What you can expect from us
When you report in good faith and give us a way to reach you, we will work with you openly and respond as quickly as our small team allows. You can expect an acknowledgement of your report within 5 business days. From there, we will tell you whether we are able to reproduce the issue, keep you posted on our progress – including anything that slows a fix down – and settle on a coordinated disclosure date together.
Rules of engagement
Before you start, please read the Ergosoft Vulnerability Disclosure: Rules of Engagement, which set out how to conduct your research, what is prohibited, and which reports fall in and out of scope. By taking part in coordinated disclosure with Ergosoft, you agree to follow them.
Recognition
Ergosoft does not run a paid bug-bounty programme and offers no monetary reward. By reporting, you acknowledge that you have no expectation of payment or compensation and waive any future claim to payment in connection with your report. At our sole discretion, and with your consent, we may credit the first reporter of a confirmed, previously unknown vulnerability in the related advisory. Any such credit is a goodwill gesture, not an entitlement.
Security advisories
When we confirm and fix a serious vulnerability affecting deployed products, we publish a security advisory on the Ergosoft website describing the issue and the remediation, so customers can assess and update.
Safe harbour
We will not pursue legal action against researchers who act in good faith and follow this policy.
Changes to this policy
Ergosoft reserves the right to modify this policy at any time, without notice, and to make exceptions on a case-by-case basis.
Contact
Ergosoft AG
Moosgrabenstrasse 13
8595 Altnau, Switzerland
Security contact: security@ergosoft.net
