Our Commitment to Product Security

The security of Maxcess products, solutions, and digital services is of the highest importance to us. We are committed to identifying, assessing, and addressing potential security risks throughout the entire product lifecycle.

Customers, partners, and independent security researchers can responsibly report potential security vulnerabilities to Maxcess. All submitted reports are reviewed and assessed according to established processes and prioritized based on their potential impact and risk.

This channel is for reporting potential security vulnerabilities to Maxcess International and does not replace Maxcess’s obligations under Regulation (EU) 2024/2847 (Cyber Resilience Act), including notifications via the ENISA Single Reporting Platform.

Confirmed vulnerabilities are coordinated with the reporter and addressed without undue delay. When a corrective or mitigating measure is available, Maxcess International provides affected users and stakeholders with relevant information regarding the affected product, impact, severity, and remediation guidance, where required and appropriate.

How to Report a Vulnerability

If you believe you have identified a security vulnerability in a Maxcess product, solution, or digital service, please submit a report using our vulnerability reporting form.

  • Product name and version
  • Detailed description of the vulnerability
  • Steps required to reproduce the issue
  • Potential impact or security risk
  • Supporting documentation, screenshots, or proof-of-concept information can be sent via email (see below)

Vulnerability Disclosure Process

1. Submission

A vulnerability report is submitted through the Maxcess Security Vulnerability Reporting channel.

2. Triage

Maxcess validates the report, assesses its potential impact, and coordinates with the reporter when contact details are provided.

3. Investigation and Validation

Technical specialists investigate the reported issue and verify the existence of the vulnerability.

4. Investigation and Remediation

Corrective or mitigating measures are developed, tested, and prepared for deployment.

5. CRA Escalation

If the report indicates active exploitation or a severe product security incident, Maxcess International initiates the required regulatory processes and informs affected users where required.

6. Disclosure and Closure

When appropriate, Maxcess International informs affected users and stakeholders about available corrective or mitigating measures. Where necessary, security advisories may be published. Disclosure may be delayed where justified by security risk. The case is closed following verification of the corrective action.

Security Resources

Vulnerability Reporting Form
Use our Security Vulnerability Reporting Form to report potential security vulnerabilities.

Report a Vulnerability

Security Contact

Maxcess Security Team: cra-security@maxcess.eu
Maxcess PGP public key: Click here to download PGP key

Technical Contact Information

Security researchers can find technical contact information in our security.txt file.
SHA-256: b196e9809844dc4122e023cfc3280d6595c6f3d7c602e652ad48a7600208fb4d