Coordinated Vulnerability Disclosure Policy

Security Contact

How to contact us: Email: security@sontex.ch

Introduction

This policy is published by Sontex SA, Rue de la Gare 27, 2605 Sonceboz-Sombeval (Switzerland), for itself and for the companies in its group (hereinafter collectively referred to as "Sontex" or "we"). Sontex SA is the manufacturer, within the meaning of Regulation (EU) 2024/2847, of the products placed on the market under the name or trademark Sontex.

Sontex is a leading provider of innovative metering technology and system solutions for the submetering industry as well as the water and energy sector.

Sontex is committed to ensuring the security of our users and systems. We appreciate the security research community, industry professionals and our customers sharing their expertise and assisting us in identifying vulnerabilities. This policy outlines our guidelines for discovering and reporting security flaws to us, and what you can expect in return.

We encourage you to contact us to report potential vulnerabilities in our systems.

Scope

This policy applies (i) to all products containing digital elements that Sontex places on the market under its name or brand – including meters and calculators, radio modules, gateways and hubs, their firmware, as well as associated software, mobile applications and cloud services – including third-party components integrated into these products, and (ii) to IT systems, applications and services owned or operated by Sontex (e.g. websites and customer portals).

Out of Scope

  • Physical testing of our facilities. (Hardware testing of Sontex devices that you legitimately own remains covered by this policy.)
  • Testing on devices, installations, or systems that do not belong to you or for which you do not have the express authorization of their owner or operator (e.g., meters installed at customers' premises or in third-party buildings), including the interception, recording, or decoding of communications (radio, wireless M-Bus, LoRaWAN, etc.) transmitted by third-party devices, is prohibited. Sontex is unable to authorize such testing.
  • Social engineering (e.g., phishing, vishing) of our employees or contractors.
  • Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks.
  • Third-party applications or services that we integrate with but do not own. Vulnerabilities found in these systems should be reported directly to the vendor according to their disclosure policy (if any). This exclusion does not apply to third-party components (software, libraries, modules) integrated into our products: please report them to us; we will coordinate the correction with the supplier concerned.

Reporting Guidelines

If you believe you have discovered a vulnerability, please assist us by following these steps:

  • E-mail your findings to our security team at security@sontex.ch.
  • Provide sufficient detail (such as the URL, the type of vulnerability, and step-by-step instructions) to allow our engineers to reproduce and verify the issue.
  • Do not take advantage of the vulnerability (e.g., downloading more data than necessary to demonstrate the issue, or deleting/modifying other users' data).
  • If you accidentally access personal data, consumption data, or confidential information, immediately stop the test, do not store, copy, or transmit this data, mention it in your report, and delete any copies as soon as we have confirmed it to you.
  • Do not disclose the vulnerability to third parties or the public before the expiry of the coordinated disclosure period specified below (section "Coordinated Disclosure"). This policy does not prevent you from reporting the vulnerability to a competent authority (e.g., a national CSIRT or ENISA in accordance with Art. 15 CRA, or the Federal Office of Cybersecurity FOCS).
  • By submitting a vulnerability, you acknowledge that you have no expectation of payment. Sontex does not operate a bug bounty program; reporting a vulnerability does not entitle you to any payment, reward, or compensation. Sontex may, at its sole discretion and with your consent, publicly mention your contribution.

Our Commitments to You

When you report a vulnerability in good faith, you can expect the following from Sontex:

  • Reports may be submitted anonymously. If you share contact information, we will acknowledge receipt of your report within 3 business days.
  • We will handle your report confidentially. We do not disclose your identity to third parties without your consent, unless required to do so by law, authority or court (see the "Data Protection" section).
  • We may share technical information about the vulnerability (without your personal data) with relevant component suppliers, our customers and the relevant CSIRTs, to the extent necessary for its analysis and correction.
  • We will keep you informed of our progress as we investigate and remediate the issue.
  • Once the security update is available, we will publish a security advisory describing the vulnerability that is fixed, in accordance with Annex I, Part II, Chapter 4 of the CRA, and notify you.

Coordinated Disclosure

We strive to correct confirmed vulnerabilities as quickly as possible, depending on their severity and the constraints of devices deployed in the field (firmware update deployments). Unless otherwise agreed, we ask that you not publicly disclose the vulnerability before the expiration of a 90-day period from our acknowledgment of receipt. If the fix cannot be made available within this timeframe, we will inform you and agree with you on a reasonable release date. The publication by Sontex of a security advisory or a notification that Sontex is legally required to make does not constitute premature disclosure.

Safe Harbour

Sontex considers security research conducted in good faith and in compliance with this policy to be authorized. In such cases, Sontex will not file a criminal complaint, initiate civil proceedings, or suspend your access to its services, provided that you:

  • Notify us of a vulnerability in a timely manner.
  • Make every effort to avoid privacy violations, degradation of our systems, and destruction or manipulation of data.
  • Do not exploit the vulnerability for any purpose other than proving its existence to our security team.
  • Keep the vulnerability details confidential in accordance with the section "Coordinated Disclosure".
  • Only test devices and systems that you own or for which you have valid authorization.

Limitations: Sontex is only bound by its own obligations. This safe harbor policy is not binding on third parties (e.g., customers, facility operators or owners, data subjects) or law enforcement authorities, and does not cover offenses prosecuted ex officio. If a third party takes legal action against you as a result of a search conducted in accordance with this policy, we will confirm upon request that the search was carried out in compliance with this policy. If you have any doubts about the compliance of a planned test, please contact us beforehand at security@sontex.ch.

Note: This policy is separate from our legal notification obligations. Under Article 14 of the CRA (applicable from September 11, 2026), we are required to notify the relevant CSIRT and ENISA, via the single notification platform, of any actively exploited vulnerability in our products and any serious incident impacting their security (early warning within 24 hours, notification within 72 hours, final report within 14 days, or one month respectively), and to inform the affected users. Other notification obligations may apply, particularly in Switzerland (Article 74a et seq. of the LSI). These notifications do not affect the coordinated disclosure process agreed upon with you, but may expedite its timeline.

Data Protection

The data controller for the personal data you provide to us as part of a report (e.g., name, email address, report content) is Sontex SA. This data is processed solely for the purposes of analyzing, coordinating, correcting, and documenting the reported vulnerability, communicating with you, and fulfilling our legal obligations, including those arising from the CRA (Cyber Resilience Act). The processing is based on our legitimate interest in ensuring the security of our products and systems, as well as our legal obligations. Your data is only shared with third parties (e.g., relevant component suppliers, CSIRT, ENISA, OFCS, authorities, or courts) to the extent necessary for addressing the vulnerability or when required by law; unless you consent, your identity is not disclosed to component suppliers. The data is retained for as long as necessary for these purposes and then deleted or anonymized in accordance with our retention policy, subject to longer legal retention obligations. Our Privacy Policy applies in all other respects. It also describes your rights (access, rectification, erasure, etc.) and our contact details.

Final provisions

By submitting a report, you confirm that you have read and agree to this policy. Sontex may modify this policy at any time; the version published at the time of the report is authoritative. This policy is governed by Swiss law. Version [1.0] of 11th September 2026.