Coordinated Vulnerability Disclosure
DC Airco places great importance on the security of our HVAC control systems and products. If you discover a vulnerability, we would appreciate it if you could inform us so we can take appropriate measures as quickly as possible.
This policy is aligned with the requirements of the EU Cyber Resilience Act (Regulation (EU) 2024/2847), including our obligations under Article 13 (vulnerability handling) and Article 14 (reporting of actively exploited vulnerabilities and severe incidents) as manufacturer of products with digital elements.
How to Report
Send to: security@dcairco.com — this is our designated single point of contact for vulnerability reports.
Requirements:
- Include "CVD" in the email subject line.
- Encrypt your report with our PGP key: https://dcairco.com/.well-known/pgp.asc.
- Include enough information to reproduce the issue (product model, firmware/software version, serial number, URL, screenshots, proof of concept if applicable).
- You may report anonymously or under a pseudonym.
What We Ask
Do not:
- Exploit the vulnerability beyond demonstrating it.
- Share the vulnerability with others until we've resolved it.
- Use physical attacks, social engineering, or spam.
- Delete or modify data not belonging to you.
Do:
- Test only on systems you own or have explicit permission to test.
- Delete any confidential information once the issue is fixed.
In Scope
- DC Airco firmware or software vulnerabilities
- Control systems (HMI, controllers, etc.)
- Web interfaces
- Insecure defaults
- Communication protocol weaknesses
- Vulnerabilities in third-party components integrated into our products (see "Third-Party Components" below)
Out of scope:
- Products past end-of-life
- DC Airco corporate IT systems (website, email)
- Vulnerabilities already publicly disclosed
- Customer support requests
Our Commitment
Response and remediation timelines, scaled to severity:
| Severity | Initial response | Assessment / status update |
|---|---|---|
| Critical / actively exploited | Within 24 hours | Within 72 hours |
| High | Within 3 business days | Within 1 week |
| Medium / Low | Within 1 week | Within 2 weeks |
- We keep you informed of progress throughout the remediation process.
- No legal action if you follow the guidelines above.
- Confidentiality maintained; personal data not shared without permission, except where we are legally required to disclose it (e.g. to regulatory authorities under the Cyber Resilience Act).
- Credit as discoverer (unless you prefer anonymity).
Regulatory Reporting Obligations
Where a reported vulnerability is being actively exploited, or results in a severe incident affecting the security of our products, we are legally obligated under Article 14 of the Cyber Resilience Act to notify the relevant national CSIRT (in the Netherlands: the NCSC) and ENISA via the EU Single Reporting Platform, following the statutory timeline:
- Early warning within 24 hours of becoming aware
- Full notification with technical details within 72 hours
- Final report within 14 days (or within 1 month for severe incidents)
Where required, we will notify affected customers of actively exploited vulnerabilities and provide guidance on mitigating measures, in parallel with our regulatory notifications.
Third-Party Components
DC Airco products may include third-party software or hardware components. If a reported vulnerability originates in such a component, we will:
- Notify the relevant upstream supplier or maintainer,
- Remain responsible for coordinating and delivering a fix to DC Airco customers, even where the underlying flaw lies outside our own codebase,
- Where upstream is unresponsive or the component is unmaintained, evaluate mitigation, forking, or replacement of the affected component.
Security Advisories
Once a reported vulnerability has been resolved, we will publish a security advisory describing:
- The affected product(s) and version(s),
- A description of the vulnerability and its impact,
- A severity rating (e.g. CVSS score),
- Remediation guidance, including how to obtain and apply the update.
Advisories will be delayed only where early publication would materially increase risk to users (e.g. before a patch is broadly available).
Questions? Email security@dcairco.com or see https://dcairco.com/.well-known/security.txt