Cybersecurity
Report a Cybersecurity Vulnerability
We take the cybersecurity of our products very seriously. If you have discovered a security vulnerability, suspected security incident, or any other security-related issue in one of our products, we encourage you to contact us as soon as possible.
Reporting a Vulnerability
Security-related reports should be sent to: security@welandsolutions.se
Please use the subject line: Security Vulnerability
We recommend including as much of the following information as possible in your report:
Product name and product version
Software version
Description of the vulnerability or incident
How the vulnerability can be exploited
Which functions or components are affected
Steps to reproduce the issue
Any evidence or technical information that may help us verify the issue
Estimated impact and severity
Any proposed remediation or mitigation measures
Contact information if you would like to receive feedback
Please do not include passwords, personal data, or any other information that is not necessary for us to investigate the matter.
What Happens After You Submit a Report?
Once we receive a security report, we will:
Acknowledge receipt as soon as possible.
Assess and verify the reported vulnerability or incident.
Evaluate any potential impact on our products and users.
Take corrective or mitigating actions where necessary.
Inform affected customers and users when relevant.
Handle any required reporting to competent authorities in accordance with applicable regulations.
Reporting Under the EU Cyber Resilience Act
For products covered by the EU Cyber Resilience Act (CRA), manufacturers have specific obligations to report actively exploited vulnerabilities and severe security incidents. Mandatory reporting under the CRA is carried out through the EU's common Single Reporting Platform (SRP), administered by ENISA. The internal email address above is intended for receiving security reports from customers, users, security researchers, and other reporting parties, and does not replace the formal reporting process required under the CRA. When we become aware of an actively exploited vulnerability or a severe security incident, specific reporting deadlines apply under the CRA. These include, among other requirements, an early warning within 24 hours and a more detailed report within 72 hours. For actively exploited vulnerabilities, a final report must be submitted no later than 14 days after a corrective or mitigating measure becomes available. For severe security incidents, a final report must be submitted within one month of the incident notification.
Responsible Disclosure
We encourage the responsible disclosure of security vulnerabilities. We ask that you:
Do not exploit a vulnerability beyond what is necessary to verify the issue.
Do not affect or disrupt our customers' or users' systems.
Do not access, modify, or delete information belonging to others.
Do not publicly disclose details of the vulnerability before we have had an opportunity to investigate and address it.
Allow us a reasonable amount of time to analyze and remediate the issue.
We will treat reported security issues confidentially to the extent possible and appropriate.