Product security and coordinated vulnerability disclosure process

At Videojet Technologies, we are committed to helping manufacturers protect the safety, quality, and authenticity of their products through reliable coding, marking, traceability, and compliance solutions. We recognise the importance of cybersecurity in today’s connected production environments and are committed to continually improving our approach to product security as the cybersecurity landscape evolves. Videojet incorporates cybersecurity considerations into product development and maintains processes for identifying, documenting, and addressing security vulnerabilities.

In response to potential cybersecurity threats, Videojet assesses reported vulnerabilities and works with appropriate internal teams to evaluate, validate, and respond to reported findings. These efforts help Videojet continually learn from information submitted by customers and security researchers and support ongoing cybersecurity improvements.

Scope

This coordinated vulnerability disclosure (CVD) process applies to the reporting of potential cybersecurity vulnerabilities in Videojet products and services. For inquiries not related to security, visit this page.

Good-faith security research

Videojet welcomes reports of potential security vulnerabilities identified through good-faith security research.

Researchers acting in good faith and in accordance with this coordinated vulnerability disclosure process are expected to:

  • Avoid actions that could negatively affect the confidentiality, integrity, or availability of Videojet products, services, customer data, or customer operations;
  • Avoid accessing, modifying, deleting, or exfiltrating data that does not belong to them;
  • Avoid testing on active production systems or customer production environments;
  • Promptly report discovered vulnerabilities to Videojet and provide sufficient information to enable validation and remediation;
  • Comply with all applicable laws and regulations.

Where researchers act in good faith, comply with this policy, and make reasonable efforts to avoid harm, Videojet does not intend to pursue legal action solely in connection with such research activities.

Nothing in this policy authorises activities that violate applicable laws, regulations, contractual obligations, or third-party rights.

Contact information and CVD submission process

Potential security vulnerabilities or privacy issues involving a Videojet product should be reported to productsecurity@videojet.com

PGP public key: security-pgp.asc

Fingerprint: 9885 18E1 BC27 74AD C5B2 F9BF 6940 8ADD 1E36 0269

Key expiration: 17 May 2029

Please do not include sensitive information such as personally identifiable information (PII), usernames, passwords, customer production data, or other confidential information in any submission.

Please provide the following information whenever possible:

  • Your contact information (name, organisation, phone number, and email address)
  • Date and method of discovery
  • Description of the potential vulnerability
  • Product name
  • Software, firmware, or product version
  • Configuration details
  • Steps required to reproduce the issue
  • Tools and methods used
  • Supporting proof-of-concept or exploitation code (if applicable)
  • Privileges required
  • Potential impact or results observed

What happens next

Upon receipt of a potential product vulnerability submission, Videojet may:

  • Acknowledge receipt of the submission, typically within five (5) business days, although response times may vary depending on the nature and complexity of the report.
  • Work with appropriate product, engineering, cybersecurity, and quality teams to evaluate and validate reported findings.
  • Contact the submitter if additional information is required.
  • Determine and implement remediation, mitigation measures, compensating controls, or other appropriate actions based on the results of the assessment and Videojet’s risk evaluation process.

Coordinated disclosure

Videojet supports the principles of coordinated vulnerability disclosure.

If a reported vulnerability is validated, Videojet may coordinate with the reporting individual or organisation regarding public disclosure. Public disclosure should generally occur only after appropriate mitigation, remediation, or other risk-reduction measures are available, unless circumstances require a different approach.

Disclosure timelines may vary depending on the nature, complexity, severity, and potential impact of the reported vulnerability.

Data protection

Videojet requests that reporters do not submit personally identifiable information (PII), customer production data, credentials, or other sensitive information when reporting a potential vulnerability unless specifically requested by Videojet and necessary for investigation purposes.

Any personal data submitted in connection with a vulnerability report will be processed in accordance with the Videojet Privacy Policy and applicable data protection laws.

Disclaimer

Videojet considers the security and safety of its products, systems, and customer information a high priority. Cybersecurity considerations are incorporated into product development and vulnerability management processes. Recent new product development efforts have included activities such as penetration testing and vulnerability assessments.

When conducting security research, please avoid any actions that could cause harm to you, our customers, or our products. Vulnerability testing may negatively affect product operation. Testing should not be performed on active production systems, and products subjected to security testing should not subsequently be used in production environments. If you have any questions, please contact a Videojet representative.

Videojet reserves the right to modify this coordinated vulnerability disclosure process at any time without notice and to make exceptions on a case-by-case basis. No specific level of response is guaranteed. If a reported vulnerability is verified and publicly disclosed, Videojet may acknowledge the reporting individual or organisation, if requested and where appropriate.

Caution

Do not include sensitive information, including PII, usernames, passwords, customer production data, or other confidential information, in any materials submitted to Videojet. Comply with all applicable laws and regulations while conducting testing activities.

By contacting Videojet, you agree that the information you provide will be governed by the Videojet Privacy Policy and Terms of Use.

Use of submitted information

Information submitted to Videojet may be used for the purpose of evaluating, validating, mitigating, remediating, and communicating regarding reported vulnerabilities.

Except as required by law, necessary to investigate or remediate a reported issue, or otherwise agreed with the reporting party, Videojet will not intentionally disclose the identity of a reporter without permission.

The handling of any personal data submitted as part of a vulnerability report is governed by the Videojet Privacy Policy.

Additional security contact information

Additional product security contact information may be available through Videojet’s security.txt file located at: https://www.videojet.com/.well-known/security.txt