Coordinated Vulnerability Disclosure Policy

Cortex Systems LLC
Effective: September 1 2026 · Version 1.0 · Canonical: https://cortex-system.com/security/disclosure-policy

1. Purpose

Cortex Systems designs and manufactures power metering and power supply products used in data center and industrial environments. We take the security of our products seriously and welcome reports from security researchers, customers, integrators, and other parties who identify potential vulnerabilities.

This policy describes how to report a vulnerability to us, what you can expect from us in return, and how we handle disclosure. It is published in accordance with our obligations as a manufacturer under Regulation (EU) 2024/2847 (the Cyber Resilience Act), Annex I Part II, and follows ISO/IEC 29147 and ISO/IEC 30111.

2. Scope

This policy covers products with digital elements made or supplied by Cortex Systems, including:

  • Cortex power meters and power quality meters, including all accessory and I/O cards
  • Embedded firmware and bootloaders for the above
  • Device web interfaces, REST APIs, and Modbus/TCP and Modbus/RTU interfaces
  • Firmware update distribution infrastructure operated by Cortex Systems
  • Cortex-published configuration and management tools

Out of scope:

  • The cortex-system.com marketing website and third-party hosted services
  • Products that have reached end of support
  • Issues requiring physical possession of a device that are already documented as accepted risk
  • Denial of service through resource exhaustion on the device network interface, unless it results in a persistent fault or bypasses a security control
  • Findings from automated scanners with no demonstrated impact
  • Social engineering of Cortex Systems staff, customers, or suppliers

3. How to report

Email security@cortex-system.com.

Please include, where possible:

  • Product model, hardware revision, and firmware version (from the device information page or the label)
  • A description of the vulnerability and its potential impact
  • Steps to reproduce, proof-of-concept code, packet captures, or screenshots
  • Whether the issue has been disclosed to anyone else, and whether you believe it is being actively exploited
  • How you would like to be credited, or whether you prefer to remain anonymous

You may report anonymously. We do not require personal information beyond a way to reach you for follow-up.

4. What you can expect from us

Milestone Target
Acknowledgment of receipt 3 business days
Initial triage and severity assessment (CVSS v4.0) 10 business days
Status updates during remediation At least every 30 days
Fix or mitigation for confirmed vulnerabilities Prioritized by severity; typically within 90 days
Public disclosure Coordinated with the reporter, see Section 6

We will keep you informed of progress, tell you when a fix is released, and credit you in the advisory if you wish.

5. Our commitments

  • We will work with you in good faith and will not take legal action against researchers who follow this policy (see Section 8).
  • We will not share your personal information with third parties without your consent, except where required by law.
  • We will request a CVE identifier for confirmed vulnerabilities in our products and publish a security advisory at https://cortex-system.com/security/advisories.
  • Where a fix requires a firmware update, we will notify registered customers and make the update available through our standard signed firmware update mechanism at no charge for products within their support period.
  • Where a vulnerability originates in a third-party or open-source component, we will coordinate with the upstream maintainer.

6. Coordinated disclosure

We ask that you give us a reasonable opportunity to remediate before disclosing publicly. Our default coordinated disclosure window is 90 days from acknowledgment of the report, or upon release of a fix, whichever comes first.

We may request an extension if remediation requires hardware changes, coordination with multiple parties, or extended customer deployment time (many of our products are installed in locations with restricted access and infrequent maintenance windows). We will explain the reason for any extension request.

If a vulnerability is being actively exploited, or if we are unable to reach agreement on timing, we will prioritize protecting affected users and may publish mitigations ahead of a full fix.

7. Regulatory reporting

As a manufacturer under the EU Cyber Resilience Act, Cortex Systems is required to report actively exploited vulnerabilities and severe incidents affecting our products to ENISA and the relevant national CSIRT through the single reporting platform, with an early warning within 24 hours and a full notification within 72 hours of becoming aware. Information you provide may be used to fulfil these obligations. We will not disclose your identity in regulatory reports without your consent.

We will also inform affected users of the vulnerability, available mitigations, and corrective measures as required by the Regulation.

8. Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized, will not pursue or support legal action against you, and will work with you to understand and resolve the issue quickly. Good faith means that you:

  • Avoid privacy violations, data destruction, and disruption of production systems; where possible, test on your own hardware
  • Do not access, modify, or exfiltrate data belonging to others
  • Do not exploit a vulnerability beyond what is necessary to demonstrate it
  • Give us reasonable time to respond before public disclosure
  • Do not demand payment or other compensation in exchange for the report

If legal action is initiated by a third party against you in connection with research conducted under this policy, we will make it known that your actions were authorized.

9. Recognition

Cortex Systems does not currently operate a paid bug bounty program. With your permission we will credit you in the associated security advisory.

10. Contact

Product security: security@cortex-system.com
Machine-readable contact: https://cortex-system.com/.well-known/security.txt
Advisories: https://cortex-system.com/security/advisories

Cortex Systems LLC, McMinnville, Oregon, USA