Coordinated Vulnerability Disclosure Policy
2wcom builds equipment and software for professional broadcast transmission. We take the security of these products seriously. We welcome reports from security researchers, customers and partners, and we treat every report confidentially and without blame.
1. Scope
This policy covers all products with digital elements placed on the market by 2wcom — devices including their firmware, associated software, and services operated by 2wcom.
It does not cover our customers’ systems, even where 2wcom products are deployed in them, nor products whose support period has ended. The support period for each product is stated in its manual.
2. How to report a vulnerability
Send your report to security@2wcom.com.
The following helps us process your report quickly:
-
Affected product, firmware or software version, hardware revision
-
A description of the vulnerability and its potential impact
-
Reproducible steps, ideally with a proof of concept
-
Your assessment of severity, if you have one
-
How we can reach you, and whether you wish to be credited by name
Please write in English or German. If you prefer encrypted communication, use our PGP key: https://2wcom.com/.well-known/pgp-key.asc (Fingerprint: 5C05 58CA 4A43 2FDE A097 F381 CD82 13B3 6BE0 E11F )
3. What we commit to
-
Acknowledgement of receipt within 3 business days.
-
Initial assessment within 10 business days — including whether we confirm the vulnerability and how we rate its severity.
-
A status update at least every 30 days for as long as the case is open.
-
We will tell you when a fix is available and agree the timing of publication with you.
-
We assess every report, including those we cannot confirm — and in that case we will tell you why.
4. Coordinated disclosure
We publish a security advisory once a fix or an effective mitigation is available to our customers.
As a guideline we aim to disclose within 90 days of receiving a report. For vulnerabilities whose remediation requires deep changes to device software, this may take longer — where that happens we will agree it with you explicitly rather than let the deadline pass in silence.
Where a vulnerability is being actively exploited or is already public, we act immediately and without regard to this timeline.
We ask you to hold publication until a fix is available, so that our customers can secure their installations. Broadcast infrastructure cannot simply be taken offline at short notice.
5. Safe harbour
If you follow this policy and act in good faith:
-
we will not initiate legal action against you, and will not support such action by third parties;
-
we consider your research authorised for the purposes of applicable laws on unauthorised access;
-
we will work with you should a third party nonetheless pursue action against you.
This assurance does not apply to deliberate harm, extortion, or disclosure of data you obtain.
6. What we ask you not to do
-
Test against our customers’ production systems. Test only on equipment you own or have explicit permission to test. Contact us if you need test equipment — we would rather lend you a device than read about an outage.
-
Denial-of-service attacks or load testing
-
Social engineering against our staff, customers or suppliers
-
Physical attacks against premises or personnel
-
Accessing, modifying or disclosing third-party data beyond what a proof of concept strictly requires
-
Publishing before the coordination described in section 4 is complete
7. Recognition
On request we will credit you in the security advisory and on our acknowledgements page.
We do not currently operate a bug bounty programme. A non-guaranteed bonus may be awarded.
8. Statutory reporting obligations
As a manufacturer, we are required under Regulation (EU) 2024/2847 (Cyber Resilience Act) to report actively exploited vulnerabilities in our products to the competent cybersecurity authority and to ENISA within 24 hours. Your report may therefore be passed to authorities. We will not disclose your identity unless you agree to it.
9. Contact
security@2wcom.com · https://www.2wcom.com/.well-known/security.txt
Last updated: 11.08.2026 · Version 1.0