General Terms for Vulnerability Disclosure

Movacolor Product Security

Document Version: 1.0
Effective Date: 11 September 2026
Owner: Isabella Galliza, System Engineer

Purpose

These Terms define how Movacolor receives, assesses, and responds to reports of potential cybersecurity vulnerabilities in Movacolor products, and set out the principles of responsible disclosure between Movacolor and the people who report such vulnerabilities. Their objective is to give security researchers, customers, and partners a clear, safe channel to report vulnerabilities, and to ensure Movacolor investigates and addresses them consistently and in line with its own legal and regulatory obligations.

Scope

These Terms apply to:

These Terms do not apply to general product support requests or bug reports that do not describe a security vulnerability.

Definitions

Vulnerability — A weakness in a Movacolor product that could be exploited to compromise its confidentiality, integrity, or availability.

Incident — An event that has already occurred (rather than a theoretical weakness) and has affected, or could affect, a Movacolor product or the systems it is connected to.

Reporter — The person or organization submitting a vulnerability report to Movacolor.

Responsible Disclosure — An understanding that a reporter will give Movacolor a reasonable opportunity to investigate and address a vulnerability before disclosing it publicly.

Roles and Responsibilities

RoleResponsibility
ReporterSubmits vulnerability reports via the reporting channel; provides accurate information to support the investigation.
MovacolorReviews and triages incoming reports; assesses impact and likelihood; coordinates remediation; communicates with the reporter and, where appropriate, affected customers.
MovacolorReports exploited vulnerabilities and severe incidents to authorities.

How to Report

Vulnerabilities can be reported to Movacolor via the vulnerability report form at movacolor.com/Product-Security. We strongly recommend using this form, as it ensures Movacolor receives the structured information needed to assess a report efficiently.

Privacy Notice

Personal information submitted as part of a vulnerability report (such as name, email address, telephone number, company, and location) is processed by Movacolor for the purpose of investigating, validating, remediating, and responding to the reported vulnerability. Movacolor may contact the reporter to request additional information, clarification, or supporting evidence, or to provide updates on the investigation and resolution. This data is processed in accordance with applicable data protection law, including the GDPR, and is used solely for vulnerability management and related security activities.

Responsible Disclosure

Movacolor appreciates cybersecurity researchers, customers, and partners who report potential security vulnerabilities in good faith.

Movacolor will not initiate legal action against individuals who conduct security research in good faith and in accordance with these Terms. Researchers must avoid privacy violations, destruction of data, service disruption, and unauthorized access beyond what is necessary to validate a vulnerability.

To facilitate an effective investigation, we request that potential vulnerabilities are reported directly to Movacolor and are not publicly disclosed before Movacolor has had a reasonable opportunity to investigate and, where appropriate, develop mitigations or corrective actions.

Movacolor's Obligations to the Authorities

Movacolor complies with applicable cybersecurity regulations, including the EU Cyber Resilience Act. Where a reported vulnerability is confirmed to be actively exploited, or where an incident qualifies as severe, Movacolor will notify the relevant authorities within the timeframes required by law. Movacolor assesses all reports against applicable legal and regulatory requirements and will notify competent authorities where notification obligations apply.

What Will Happen Next?

Movacolor's Communication with Customers When an Issue is Fixed

Where a reported vulnerability affects a product in use by customers, Movacolor will inform affected customers once a fix, mitigation, or other corrective action is available, through Movacolor's usual customer communication channels. Where appropriate, this communication will describe the issue, the affected product(s) and version(s), the corrective action taken or recommended, and any action the customer needs to take. In addition, Movacolor will publish a Security Advisory on the Product Cybersecurity webpage (movacolor.com/Product-Security) describing the issue and the corrective action taken.