Product Security

At MICROTRAC, we take the security of our products seriously. Cybersecurity is an integral part of how we design, develop and maintain our encoders and measurement solutions throughout their entire lifecycle. In line with the EU Cyber Resilience Act (CRA), we are committed to transparency about how we handle vulnerabilities and how they can be reported to us.

Below you will find our Coordinated Vulnerability Disclosure Policy, along with instructions on how to report a suspected vulnerability or security incident.

Coordinated Vulnerability Disclosure Policy

Adopted under Article 13(8) and Annex I, Part II, point 5 of Regulation (EU) 2024/2847 (Cyber Resilience Act).

Microtrac Fomulaction S.A.S. (FR) / Microtrac Inc. (US) / Microtrac Retsch GmbH (DE) / MicrotracBEL Corp. (JP) welcome reports of security vulnerabilities in their products with digital elements and handle them confidentially and promptly.

Scope

This policy covers all MICROTRAC products with digital elements placed on the EU market, including their firmware, software and associated online services, for the duration of the applicable support period.

How to report

Email
product-security@microtrac.com

Languages
English, German

Please include: affected product and version, description of the issue, steps to reproduce, potential impact, and your contact details. Incomplete reports are welcome – report early rather than waiting for completeness.

Our commitments

Step Target
Acknowledgement of receipt 3 business days
Status updates at least every 30 days
Remediation (critical vulnerabilities) 30 days
Publication of advisory after a fix is available

Coordinated disclosure & good faith

We ask reporters to allow a reasonable remediation period – as a guideline 90 days – before public disclosure. Anyone who reports in good faith and in line with this policy will not face legal action from MICROTRAC based on their research.

Reporting to authorities (Article 14 CRA)

Where a report concerns an actively exploited vulnerability, MICROTRAC is required to notify the competent CSIRT and ENISA within 24 hours. Please flag this explicitly if known to you.

Confidentiality

Reports are treated confidentially and personal data is processed in line with the GDPR. No paid bug bounty programme exists; credit in the published advisory is offered on request.

Document control - Microtrac Fomulaction S.A.S. (FR) / Microtrac Inc. (US) / Microtrac Retsch GmbH (DE) / MicrotracBEL Corp. (JP) Coordinated Vulnerability Disclosure Policy, version 1.0, effective 11 September 2026. Approved by Marko Ortner, Head of R&D.

Questions about this policy: product-security@microtrac.com

Report a Security Vulnerability

Single point of contact under Article 13(8) Regulation (EU) 2024/2847 (Cyber Resilience Act).

Email
product-security@microtrac.com

Languages
English, German · anonymous reports accepted

Actively exploited?
Say so explicitly in your report – this triggers our 24-hour notification duty to the competent CSIRT / ENISA under Article 14 CRA.

What to include

  • Affected product and version
  • Description of the vulnerability and steps to reproduce it
  • Potential impact
  • Your contact details (or state if you wish to remain anonymous)

What you can expect

Acknowledgement within 3 business days, regular status updates, and a coordinated disclosure timeline – details in our Coordinated Vulnerability Disclosure Policy (see above). Security updates are always free of charge.

Please do / do not

Do: test only your own systems, report promptly, keep details confidential until disclosure is agreed.
Do not: access others' data, disrupt production systems, or request payment for your report.

Incident Report Form