Slide 1

Vulnerability Disclosure

Chemelex builds electric heat trace, leak detection, and associated sensing products that protect critical processes, infrastructure, and systems. Some of these products contain software, firmware, or connected services. We treat the security of those products as part of their quality.

This page explains how to report a suspected security vulnerability in a Chemelex product, and what Chemelex does after it receives your report. It is our coordinated vulnerability disclosure policy for the public. It applies to everyone: customers, partners, security researchers, and members of the public.

Report a vulnerability

Use this single point of contact for all suspected product security vulnerabilities. Do not use the general contact form, and do not post the details in public.

What to include

A complete report helps us confirm the problem quickly. Please tell us:

  • The product name, model, and brand.
  • The software or firmware version, and the hardware revision if you know it.
  • A description of the vulnerability and the security impact.
  • The steps to reproduce the behavior.
  • Any proof of concept code, logs, network captures, or screenshots.
  • Your name and contact details, or a statement that you want to stay anonymous.
  • Your disclosure plans, if you have any.

Write in English if you can. If you cannot, send the report in your own language. We will translate it.

If a vulnerability puts safety or life at risk, write SAFETY IMPACT in the subject line.

Email: productsecurity@chemelex.com

Scope

This policy covers Chemelex products with digital elements and the services that support them, for the declared support period of each product.

 In Scope

Out of Scope 

  1. Controllers, thermostats, and monitoring devices sold under the Raychem, Pyrotenax, Tracer, and Nuheat brands.
  2. Embedded software and firmware in those devices.
  3. Connected platforms and applications that Chemelex operates for those devices.
  4. Mobile and desktop applications that Chemelex publishes.
  5. Chemelex websites, web applications, and customer portals.
  6. Third-party and open-source components inside the products above.
  1. Websites and services that Chemelex does not own or operate.
  2. Findings that show a missing hardening measure but no security impact.
  3. Denial of service tests, load tests, and spam.
  4. Social engineering of Chemelex employees, customers, or partners.
  5. Physical attacks on Chemelex sites, staff, or equipment in the field.
  6. Automated scanner output that you have not reviewed.

Send the report even if you are not sure that a product is in scope. We will route it to the correct team.

What to Expect

Chemelex handles each report through a documented process. These are our target times.

3 business days: We confirm that we received your report and give you a tracking reference. We use this reference in all later messages

10 business days: We complete triage. We tell you whether we reproduced the problem, which products and versions are affected, and how we rate the severity. We rate severity with the Common Vulnerability Scoring System (CVSS) version 4.0

Every 30 days: We send you a status update until we close the report. You can ask for an update at any time

Without undue delay: We develop, test, and release a security update or a mitigation. The schedule follows the cybersecurity risk to users. High risk gets priority

90 days, target: We publish a security advisory and coordinate the disclosure with you. We agree a different date with you when a fix needs more time

Some Chemelex products run in plants and buildings that use planned maintenance windows. A safe rollout can take longer than a software-only product. We explain the reason when this happens.

Coordinated disclosure

Chemelex supports coordinated vulnerability disclosure. We ask you to give us a reasonable time to investigate and to release a fix before you publish the technical details. In return, we keep you informed, we credit your work if you want credit, and we agree the disclosure date with you.

We publish the details of a vulnerability after a security update or a mitigation is available to users. We can delay publication when early disclosure creates more risk than it removes. Examples are:

  • Users need more time to install the update on operational equipment.
  • The same component affects other manufacturers, and the disclosure needs coordination.
  • The fix is not yet complete, and the details would enable attacks.
  • We tell you when we delay publication, and we explain why.

Guidelines for researchers

We welcome reports from security researchers. Please follow these rules while you test.

Please do

  • Test only equipment and accounts that you own, or that the owner has authorized you to test.
  • Stop as soon as you have proof of the vulnerability.
  • Report the finding to us promptly.
  • Keep any data that you find confidential, and delete it after you report.
  • Keep the report confidential until we agree a disclosure date.

Please do not

  • Test live installations, plant equipment, or any system that others depend on.
  • Access, change, or delete data that belongs to another person or organization.
  • Degrade or interrupt a service.
  • Use social engineering, phishing, or physical intrusion.
  • Install a backdoor, or keep access after you finish testing.
  • Ask for payment in exchange for the details of a vulnerability.

How we treat your research

Chemelex supports good-faith cybersecurity research. If you report a vulnerability in accordance with this policy, act in good faith, avoid privacy violations, service disruption, data destruction, and unauthorized disclosure of information, and give us a reasonable opportunity to remediate before you disclose publicly, Chemelex will not take legal action against you for that research. We will work with you to resolve the issue. If a third party takes action against you for work that followed this policy, we will make that good faith clear.

This statement covers Chemelex only. It cannot waive the rights of customers, partners, or other third parties, and it cannot override the law in your country.

Chemelex does not operate a bug bounty program and does not pay for vulnerability reports. With your permission, we name you in the security advisory.

Security advisories

Chemelex publishes product security advisories as Tech Notes. You can find them on the Downloads page and in the product security advisory list. Customers can subscribe to receive new advisories by email.

We publish an advisory when a vulnerability can significantly affect product security or safety, when you must act to apply a mitigation or a security update, when exploitation is known or suspected, or when the information is necessary for the secure operation of the product.

Each advisory contains the information that you need to act:

Please provide valid dimensions to display the simple table

Security updates and support

Chemelex supplies security updates for products with digital elements at no cost. We distribute them through the approved update mechanism for each product, and we protect the integrity of the update.

Where we can do so, we separate a security update from a functional update. This lets you install the security fix without a functional change.

Support period

Each product with digital elements has a declared support period. The product documentation states the period. Chemelex handles vulnerabilities and supplies security updates for the whole support period. We keep each security update available for at least 10 years after we release it, or for the rest of the support period, whichever is longer.

Software bill of materials

Chemelex maintains a software bill of materials for products with digital elements in a common machine-readable format. Customers can request the software bill of materials for a product through productsecurity@chemelex.com.

Third-party and open-source components

Chemelex products contain third-party and open-source components. We monitor those components for vulnerabilities, and we assess each vulnerability against the product that uses it.

Our suppliers of software, firmware, cloud services, and digital components must tell us about vulnerabilities, known exploits, security advisories, and available remediations that affect our products.

When we find a vulnerability in a component, we report it to the person or organization that maintains the component. When we develop a fix for that component, we offer the code or the documentation to the maintainer.

Regulatory reporting

Chemelex meets the reporting duties of Regulation (EU) 2024/2847, the Cyber Resilience Act. We report actively exploited vulnerabilities and severe security incidents through the single reporting platform of the European Union, to the coordinating CSIRT and to ENISA.

Report

Deadline After We Become Aware

Early Warning

24 hours

Vulnerability or incident notification

72 hours

Final Report

14 days after a corrective measure is available

Regulatory reporting and public disclosure are separate activities. We do not delay a regulatory report to wait for an advisory, and we do not release advisory details early because a regulatory report is due.

Document information

Document

Vulnerability Disclosure, public statement

Version

1.0.0 September 07, 2026

Effective date

To be confirmed

Owner

Product Cybersecurity

Review cycle

Annual, or after a process change

Related

Coordinated Vulnerability Disclosure Policy, version 1.0.0 (PDF)