Report a Security Vulnerability

Found a potential security issue in one of our products or services? Tell us. We handle every report through our coordinated vulnerability disclosure process, in line with the EU Cyber Resilience Act (Regulation (EU) 2024/2847).

Product Security Team

Prefer email? Contact us directly:

Email: security@sensile.com
PGP key: Download
Fingerprint:
1A36 7309 0DE1 9CD7 934E FFAB DFEE D417 1E68 27C7
security.txt: /.well-known/security.txt

Sensile Technologies SA
Rue de Lausanne 45
CH-1110 Morges
Switzerland

For general or sales questions, please use our regular contact page. For device support, contact your local distributor.

What happens next

  • Acknowledgementwithin 2 business days
  • Initial assessmentwithin 10 business days, incl. severity rating
  • Remediationfix or mitigation developed; regular status updates to you
  • Security advisorypublished once a fix is available, with credit if desired

Actively exploited vulnerabilities and severe incidents are reported to the CSIRT/ENISA within 24 h (early warning), 72 h (notification) and 14 days (final report), as required by CRA Article 14.

Scope

  • Sensile hardware & firmware
  • Web platform, mobile apps and APIs
  • Third-party components shipped in our products

Please do not perform tests that could disrupt service to customers (DoS, social engineering, physical attacks).