CVD Policy
Coordinated Vulnerability Disclosure Policy
Last updated: 11 August 2026
Carl Cloos Schweißtechnik GmbH and Estun Robotics Europe AG welcome reports from security researchers and the public. We take every report seriously and investigate all legitimate submissions.
Scope:
This policy applies to:
- CLOOS software products: C-Gate, QNECT, Roboplan and other CLOOS PC-Products
- CLOOS Robotic- and welding systems
- Estun Robotics Europe products with digital elements
Out of scope: social engineering, physical attacks, denial of service testing, spam, and issues in third-party services we do not control.
How to report :
Email security-reports@cloos.de with:
- A description of the issue and where it was found (product + version)
- Steps to reproduce (proof-of-concept code or screenshots help)
- Impact as you understand it
If you prefer encrypted mail, our PGP key is available at this link.
What we commit to:
- Acknowledgement within 3 business days.
- We will keep you informed of progress toward a fix.
- We aim to remediate confirmed vulnerabilities within 90 days; for actively exploited vulnerabilities we act immediately and comply with our reporting obligations under Article 14 of the EU Cyber Resilience Act.
Safe Harbour:
We will not pursue legal action against researchers who:
- Make a good-faith effort to follow this policy
- Avoid privacy violations, data destruction, and service degradation
- Do not access or modify data beyond what is needed to demonstrate the issue
- Give us reasonable time to remediate before public disclosure
Thank you for helping keep our users safe.