Scope
This policy covers cyber vulnerabilities affecting the Sipro products currently supported:
- Siax M-EVO
- Siax A-EVO
- Siax XPC
- HMIS Series
Sipro has adopted a Coordinated Vulnerability Disclosure policy in compliance with EU Regulation 2024/2847, ensuring advanced protection and operational continuity for its products and partners.
A structured, transparent and responsible approach to safeguarding the integrity of automation systems.
The cyber resilience of our motion control systems is a core requirement. We continuously design and test hardware, firmware and software applications to meet the most demanding security standards in the industrial sector.
In line with EU Regulation 2024/2847, we foster an ecosystem of open collaboration with customers, partners and security researchers, so that any potential vulnerability can be identified and mitigated in advance.
Guidelines and operating procedures for reporting and securely handling vulnerabilities.
This policy covers cyber vulnerabilities affecting the Sipro products currently supported:
We ask that you act ethically in order to protect the operation of live plants:
Sipro undertakes not to take legal action against anyone acting in good faith and in accordance with these guidelines.
To allow us to analyse and reproduce the vulnerability, please include the following information in your report:
📧 Email: Contact our Cyber Security team directly, providing the required information, at:
🔐 Encryption recommended: if your report contains sensitive information, we recommend encrypting the message with our PGP public key, so that confidentiality is preserved until the fix is released.
We guarantee a fast, traceable resolution process, promptly notifying the relevant authorities (CSIRT / ENISA) in the cases required by law: