Skip to main navigation Skip to main content Skip to page footer

CVD Policy

Coordinated Vulnerability Disclosure Policy

Last updated: 11 August 2026
Carl Cloos Schweißtechnik GmbH and  Estun Robotics Europe AG welcome reports from security researchers and the public. We take every report seriously and investigate all legitimate submissions.


Scope:

This policy applies to: 

  • CLOOS software products: C-Gate, QNECT, Roboplan and other CLOOS PC-Products
  • CLOOS Robotic- and welding systems
  • Estun Robotics Europe products with digital elements

Out of scope: social engineering, physical attacks, denial of service testing, spam, and issues in third-party services we do not control.


How to report :

Email security-reports@cloos.de with:

  • A description of the issue and where it was found (product + version)
  • Steps to reproduce (proof-of-concept code or screenshots help)
  • Impact as you understand it

If you prefer encrypted mail, our PGP key is available at this link.


What we commit to:

  • Acknowledgement within 3 business days.
  • We will keep you informed of progress toward a fix.
  • We aim to remediate confirmed vulnerabilities within 90 days; for actively exploited vulnerabilities we act immediately and comply with our reporting obligations under Article 14 of the EU Cyber Resilience Act.


Safe Harbour:

We will not pursue legal action against researchers who:

  • Make a good-faith effort to follow this policy
  • Avoid privacy violations, data destruction, and service degradation
  • Do not access or modify data beyond what is needed to demonstrate the issue
  • Give us reasonable time to remediate before public disclosure

Thank you for helping keep our users safe.