Cibersecurity
Soler & Palau Ventilation Group Product Safety Policy
At Soler & Palau Ventilation Group we are committed to the safety, reliability and resilience of our products and equipment in compliance with the provisions of Regulation (EU) 2024/2847, known as the Cyber Resilience Act (CRA).
We recognize the value that customers and third parties bring in the responsible identification of potential vulnerabilities that may affect our products/equipment.
For this reason, Soler & Palau promotes the responsible notification of vulnerabilities and maintains procedures for their analysis, evaluation, prioritization and resolution.
Principles of responsible disclosure
S&P requests that anyone who identifies a potential vulnerability:
-
Always act in good faith and in accordance with applicable law.
-
Avoid any action that may compromise the confidentiality, integrity, or availability of systems, data, or services.
-
Do not access, modify, or delete information that does not belong to you.
-
Do not publicly disclose details of the vulnerability until S&P has had a reasonable opportunity to analyze it and take appropriate corrective action.
-
Cooperate with S&P during the assessment and remediation process.
Management of reported vulnerabilities
Upon receipt of a communication:
-
S&P will acknowledge receipt of the notification within 5 business days
-
A preliminary assessment will be conducted to determine the validity and scope of the reported vulnerability.
-
Additional information may be requested from the reporter when necessary.
-
The vulnerability will be classified and prioritized according to its criticality and potential impact.
-
Appropriate corrective measures will be analysed and implemented, where appropriate.
-
S&P will be able to keep the reporter informed of the most relevant developments in the process.
Vulnerabilities will be managed in accordance with the organization's internal vulnerability management procedures.
Communications and Safety Notices
When a vulnerability significantly affects the security of a product or requires action by customers or users, S&P may publish security communications or advisories that include:
-
Affected products and versions.
-
Nature and severity of vulnerability.
-
Potential impact.
-
Recommended mitigation measures.
-
Availability of updates, patches, or corrective actions.
Such communications may be published through the corporate website, technical documentation or any other channel that S&P deems appropriate.
Scope
This policy applies to all products with digital elements developed, manufactured or marketed by S&P, including firmware, embedded software, mobile applications, cloud platforms and digital services for which S&P is responsible for security.
Commercial enquiries, ordinary technical support incidents and any other matters not related to security vulnerabilities are excluded from this policy.
Vulnerability Reporting
If you believe that you have identified a potential security vulnerability affecting a product/equipment, application, digital service or platform managed by S&P, please let us know by completing the form below:
The information received will be treated confidentially and used exclusively for the assessment and mitigation of the reported vulnerability.