Report a security vulnerability

Help us keep our connected coffee machines and digital services secure.

Report a security vulnerability

The security of our connected coffee machines and digital products is important to us. If you discover a security vulnerability, please report it to us responsibly so that we can investigate and resolve the issue.

Scope

This policy applies to connected commercial coffee machines, associated apps, cloud services and web portals provided by ETNA Equipment B.V.

Reporting guidelines

When reporting a vulnerability, please:

  • notify us promptly;

  • avoid exploiting the vulnerability beyond what is necessary to demonstrate its existence;

  • do not access or modify data belonging to others;

  • keep the vulnerability confidential until we have resolved the issue.

How to report a vulnerability

You can submit a vulnerability through our:

Secure web form
E-mail via: security@etna-ct.com

Please include:

  • a description of the vulnerability and its potential impact;

  • the affected product model and software version;

  • the steps or a proof-of-concept required to reproduce the issue.

What you can expect from us

Acknowledgement
We will acknowledge receipt of your report within 7 calendar days.

Communication
We will keep you informed of our progress while we investigate and remediate the issue.

Safe Harbor
We will not take legal action against security researchers acting in good faith and in accordance with this policy.