1. Purpose
Agileo Automation values reports from security researchers, customers, partners and users. This vulnerability disclosure policy explains how to report a potential security vulnerability in Agileo Automation products, software, and public websites so that Agileo Automation can assess the issue, coordinate remediation where needed, and help reduce security risk for its customers.
2. Scope
This policy applies to vulnerabilities affecting:
• Agileo Automation products and software during their defined support period.
• Agileo Automation websites and APIs.
• Third-party components integrated into or distributed as part of an Agileo Automation product, where a vulnerability may affect the security of that product.
This policy does not authorize access to or testing on customer environments, customer equipment, production systems or fabs, partner systems, third-party systems, or other non-public systems unless Agileo Automation has explicitly authorized the testing in writing. Any vulnerability identified in such environments must be reported to the relevant owner.
Issues in products, software or systems not developed, operated or maintained by Agileo Automation, should be reported to the relevant vendor. You may still inform Agileo Automation if you believe an Agileo Automation product or customer deployment is affected.
3. How to report a vulnerability
Send your report to:
Use the subject line: " Vulnerability report "
Please submit reports in English where possible and include, when available:
• affected product, service, URL or environment with concerned versions and configurations.
• vulnerability description.
• steps to reproduce using a benign proof of concept.
• possible security impact.
• screenshots, logs or technical evidence.
• your contact details and, where applicable, the name of your organization.
If you believe the vulnerability is being actively exploited, use “ Actively exploited vulnerability report ” as the subject line and provide all available evidence, including indicators of compromise, observed exploitation, affected versions and dates of observation.
Note: This email address is intended only for reporting potential security vulnerabilities affecting Agileo Automation products, software or public websites. Unrelated commercial, marketing or support requests may not receive a response.
4. Security researcher guidelines
Do not:
• break the law or violate privacy.
• access, modify, delete, extract or disclose data.
• disrupt services or perform denial-of-service testing.
• use phishing, social engineering or physical attacks.
• install malware, backdoors or persistent access.
• disclose the vulnerability publicly before coordination with Agileo Automation.
If you access personal, confidential or customer data by accident, stop testing immediately, do not copy, retain, transfer or disclose the data, and report the incident to Agileo Automation without delay.
5. What to expect from Agileo Automation
Agileo Automation treats vulnerability reports as part of its broader commitment to secure software, industrial cybersecurity, responsible coordination and long-term customer trust.
Agileo Automation will:
• acknowledge receipt within 5 business days, with urgent reports involving suspected active exploitation or severe security impact handled without undue delay.
• triage the report and aim to provide an initial assessment within 10 business days, except where faster assessment is required because of the severity of the issue or applicable legal obligations.
• prioritize remediation according to severity, exploitability, customer impact and product support status.
• keep the reporter informed when contact details are available and when useful for remediation, investigation or coordination, taking into account confidentiality, customer protection and applicable legal obligations.
• notify the reporter when the vulnerability is fixed or mitigated, when appropriate.
6. Vulnerability disclosure
Agileo Automation asks reporters to allow reasonable time for investigation, remediation and customer coordination before any public disclosure. Disclosure timing will depend on severity, exploitability, availability of mitigations, customer impact and any applicable legal obligations.
Agileo Automation will coordinate any public disclosure, security advisory or customer notification where needed. Agileo Automation will also assess whether the report triggers customer notification, authority reporting or other legal obligations.
Where a vulnerability is confirmed, Agileo Automation may share relevant information with affected customers, suppliers, competent authorities, CSIRTs or other coordination bodies when this is necessary to reduce risk, comply with legal obligations or support remediation.
Where required by applicable law, Agileo Automation will publish information about fixed vulnerabilities, including information necessary to identify affected products, the vulnerability impact and severity, and available remediation. Publication may be delayed where permitted by law and where immediate disclosure could increase security risk.
Reporters should not publish exploit code, technical details enabling exploitation, or information that could increase customer risk before coordination with Agileo Automation. Public disclosure should only take place after coordination with Agileo Automation, unless otherwise required by law.
7. Closure of a vulnerability report
Agileo Automation may close a vulnerability report when:
• the reported issue is not confirmed as a vulnerability;
• the vulnerability has been fixed, mitigated or otherwise appropriately addressed;
• affected customers have been informed, where required or appropriate;
• the vulnerability has been publicly disclosed in coordination with Agileo Automation; or
• the reported product, software or service is outside the scope of this policy.
Agileo Automation will inform the reporter of the closure when contact details are available and when doing so is appropriate.
8. Legal
Agileo Automation does not offer monetary rewards for vulnerability reports.
Agileo Automation does not intend to take legal action against good-faith security research that complies with this policy, to the extent Agileo Automation is legally able to make that commitment. This policy does not prevent Agileo Automation from taking action where research causes harm, violates the law, affects third-party rights, compromises customer environments, or creates a risk to safety, security, privacy or service continuity.
9. Questions
For questions about this policy or the status of a submitted report, contact
To help the team focus on investigation and remediation, please avoid status requests more than once every 14 days unless the situation is urgent.
10. Policy Review
This policy will be reviewed periodically and updated when needed to maintain its effectiveness, reflect changes in Agileo Automation products and services, and remain aligned with applicable legal, cybersecurity and customer protection requirements.