Version 1.0 — Valid from 11/09/26
1. Our commitment
We design and manufacture electronic components for lifting equipment. Some of our products incorporate firmware and communication interfaces, and like any software system, they may contain vulnerabilities.
We regard the responsible reporting of a vulnerability as a contribution to the security of our customers and the end users of our products. This policy describes how to report a security issue to us, what we undertake to do in response, and what we ask of those who report issues.
Our process is based on the ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability management) standards, and on the requirements of Regulation (EU) 2024/2847 (the Cyber Resilience Act).
2. How to report
Single point of contact: cybersecurity@vegalift.it
This is the only dedicated channel for reporting safety issues relating to our products. Please do not use the technical or sales support channels: they slow down the handling of your report and do not guarantee confidentiality.
If you believe that the technical details of your report require special protection, please let us know when you contact us and we will agree on a suitable communication channel with you before going into detail.
What to include in the report
The more information provided, the quicker we can verify and rectify the issue. We would ask you, as far as possible, to provide:
- the product and model concerned, and the firmware version if known;
- a description of the vulnerability and its potential impact;
- steps to reproduce the issue, including any specific configurations;
- the test environment used (test bench, uninstalled device, live system);
- any test code, screenshots or traffic captures;
- whether you wish to be publicly acknowledged in the advisory, and by what name.
Anonymous report
If you prefer not to reveal your identity, you can report the vulnerability indirectly via the CSIRT designated as the coordinator for the coordinated disclosure of vulnerabilities. In Italy, this is CSIRT Italia, based at the National Cybersecurity Agency. The CSIRT will forward the report to us whilst preserving your anonymity.
3. Covered products
This policy applies to all Vegalift-branded hardware and firmware products currently available on the market or within their respective support periods, and to the software applications that accompany their installation and configuration.
This policy also covers vulnerabilities in third-party components integrated into our products (communication modules, libraries, network stacks): please report these to us anyway, and we will coordinate with the relevant supplier.
The following are excluded from this policy: our corporate IT systems, the corporate website, email services and any third-party platforms we use. For issues relating to these systems, please email cybersecurity@vegalift.it and we will ensure the report is routed internally.
4. Personal safety: what NOT to do
Our products are installed on lifting equipment in service, which is used by people. This is the most important point of this policy.
| Do not carry out tests on installed and operational systems. No exceptions. Interfering with a system that is in service may cause harm to people, and no research objective justifies this. |
We also ask that you:
- limit testing to bench-top equipment that is not connected to a live system;
- do not attempt denial-of-service attacks, nor carry out load or stress tests on live systems;
- do not access, modify, exfiltrate or retain data that does not belong to you, and cease the activity immediately if you come across third-party data;
- refrain from using social engineering against our employees, customers or installers, and from gaining unauthorised physical access to our premises or equipment rooms;
- not to disclose the vulnerability publicly before the coordinated disclosure procedure described in point 6 has been completed.
5. What we are committing to do
| Phase | Timings |
| Confirmation of receipt of the report | within 3 working days |
| Outcome of the initial assessment and commencement of care | within 10 working days |
| Progress updates | at least every 30 days |
| Availability of the correction or mitigation measure | Target: 90 days from confirmation |
We also undertake to:
- assign a tracking ID to every report and provide you with it;
- inform you if we consider the report to be non-reproducible or outside the scope of this policy, explaining why;
- not to take or support any legal action against you for research carried out in good faith and in accordance with this policy;
- to publicly acknowledge you in the advisory, if you wish, or to maintain your anonymity if you prefer;
- to involve the upstream vendor when the vulnerability lies in a third-party component, in parallel with our own remediation efforts.
A clarification regarding the timeframe for applying fixes. Firmware updates for our products are not carried out remotely: they require on-site intervention by qualified technical staff. The availability of a fix and its actual application to installed systems are therefore two distinct stages, and the latter may take significantly longer. We take this into account when coordinating the disclosure process.
We do not currently offer financial rewards for reports of vulnerabilities.
6. Coordinated dissemination
The aim of coordinated disclosure is to give users the opportunity to protect themselves before the technical details become public.
We ask that you do not publicly disclose the details of the vulnerability for 90 days from our acknowledgement of receipt, or until the publication of our advisory, whichever comes first. If the fix takes longer — which is possible for the reasons outlined above — we will contact you to agree on an extension, providing a reason for it.
When a fix or mitigation measure becomes available, we publish a security advisory on https://mega.vegalift.it/hc/it/articles/30008798138396-Advisory-list, containing:
- the CVE identifier, where assigned;
- the affected products and firmware versions;
- a CVSS severity rating;
- a description of the impact;
- operational instructions for installers and any applicable mitigation measures to be taken whilst awaiting a fix.
We may delay public disclosure only where we consider, on duly justified grounds, that the risks of immediate disclosure outweigh the benefits, and only for as long as is necessary to allow users to apply the fix. In such cases, we document the reasons for doing so.
7. Duty to report to the authorities
In the interests of transparency, we would like to inform you that, should we ascertain that a vulnerability in our products is being actively exploited, we are required by law to report it to CSIRT Italia and ENISA via the single reporting platform, within 24 hours of becoming aware of it, in accordance with Article 14 of Regulation (EU) 2024/2847.
This notification relates to the vulnerability and its exploitation. We do not disclose your identity to the authorities without your consent.
8. Contacts and revisions
Single point of contact for security vulnerabilities: cybersecurity@vegalift.it
Registered office:
Vegalift S.r.l. Via degli Appennini 11-13, Contrada Capparuccia, 63845 - Ponzano di Fermo (FM) Italy