Vulnerability Disclosure Policy

Purpose

Ammann recognizes cybersecurity as an important requirement for customers using products with digital elements. We are committed to supporting customers by providing products, systems, and services that address cybersecurity in a clear and responsible way. This Vulnerability Disclosure Policy provides a structured mechanism for external parties to report suspected vulnerabilities and product security incidents so that they can be assessed, handled, and remediated in a timely manner, helping customers minimize cybersecurity risks.

Scope

This policy applies to suspected vulnerabilities and product security incidents affecting Ammann products with digital elements.

If you are unsure which product, system, or component is affected, please select “Other / Unknown” in the reporting form.

Responsible Disclosure

When testing or reporting a suspected vulnerability, please:

  • Act in good faith.

  • Respect privacy and avoid accessing data beyond what is necessary to identify the issue.

  • Avoid disrupting systems, services, customers, or operations.

  • Do not modify, delete, or exfiltrate data.

  • Do not establish persistence, move laterally, deploy malware, or perform destructive testing.

  • Stop testing and report the issue immediately if you gain access to non-public, customer, production, or safety-relevant systems or data.

  • Do not publicly disclose vulnerability details until coordinated disclosure has been agreed.

Information to Include

To help us assess and handle your report, please include the following information, where available:

  • Contact information.

  • Affected Ammann product, service, system, or component.

  • Product model, software version, or firmware version.

  • Description of the suspected vulnerability or security issue.

  • Steps to reproduce the issue.

  • Potential security impact.

  • Any indication that the issue is being actively exploited.

Ammann may contact you if additional information is required.

Do not submit malware, exploit binaries, destructive proof-of-concept code, or executable files unless specifically requested by Ammann.

Vulnerability Handling Process

After receiving a report, Ammann will assess whether it affects an Ammann product, system, software, or digital service. Reports will be prioritized based on factors such as severity, exploitability, affected products, and potential impact.

Where appropriate, Ammann will investigate, remediate, and coordinate disclosure of validated vulnerabilities. Vulnerability information may be published after a fix, mitigation, or security update becomes available.

Coordinated Disclosure

We ask reporters to avoid publicly disclosing vulnerability details until Ammann has had a reasonable opportunity to investigate and address the issue. Where appropriate, Ammann will work with the reporter to coordinate any disclosure.

No Bug Bounty

Ammann does not operate a public bug bounty or reward program, and vulnerability reports are submitted without expectation of compensation.

Data Protection

Information submitted through the reporting process will be used to assess, investigate, and remediate the reported security issue. Personal data will be processed in accordance with the applicable Ammann Data Protection Notice.

Security Contact

If the reporting form is unavailable, vulnerability and product security reports may be sent to:

security@ammann.com

This email address is not intended for general support requests.

For incident reports related to Q-Point products, please submit the report at q-point.com.