Coordinated Vulnerability Reporting

Nerospec SK GmbH (NSK) takes the security of our products seriously. We welcome reports from security researchers, customers, and users who discover a potential vulnerability in any product with digital elements developed, manufactured, or distributed by NSK. 

HOW TO REPORT

Send a report to nsk-security@nerospec.com, including as much of the following as you can:

  • A description of the vulnerability and its potential impact
  • The affected product and version, where known
  • Steps to reproduce, or a proof of concept
  • Your contact details, so we can follow up

Please do not include sensitive personal data in your report unless it is directly necessary to demonstrate the issue. 

WHAT TO EXPECT

  • We aim to acknowledge receipt of your report within 3 business days.
  • We will assess and, where confirmed, work on a fix, keeping you informed of progress at reasonable intervals.
  • Once a fix or mitigation is available, we will coordinate with you on the timing of any public disclosure. Where no fix is available, we ask that details remain confidential for up to 90 days from your initial report, or until a fix is released, whichever comes first — unless we agree on a different timeline together 

SCOPE AND SAFE HARBOUR

We support good-faith security research and will not pursue legal action against researchers who:

  • Make a genuine, good-faith effort to identify and report a vulnerability privately to us first,
  • Avoid privacy violations, data destruction, or service disruption,
  • Do not access, modify, or exfiltrate data beyond what is strictly necessary to demonstrate the issue, and
  • Give us a reasonable opportunity to investigate and remediate before any public disclosure.
  • Important — safety-critical systems: NSK’s products are used to control and monitor heavy mobile equipment, including autonomous and remotely operated mining vehicles. For safety reasons, testing against live, operational, or production systems (including any deployed vehicle, fleet platform, or operator station) is out of scope and must not be attempted without NSK’s prior written authorization. Testing should be limited to non-operational, isolated, or provided test environments. Reports based on responsible analysis (e.g. of documentation, firmware images, or a test environment) are welcome even without live-system testing. 

Contact

nsk-security@nerospec.com

Last updated: 1 September 2026

Scroll to Top

Download Automation brochure

Enter your name and email address to download the automation brochure.