Product Security Incident Response Team - Tria

PRODUCT SECURITY INCIDENT RESPONSE TEAM

Working Together for Stronger Product Security

Security is a fundamental element of the products, software, and services provided by Tria Technologies.

The Tria Technologies Product Security Incident Response Team (PSIRT) serves as the central point of contact for reporting potential security vulnerabilities affecting our hardware platforms, embedded systems, firmware, software solutions, and cloud-based services.

Our PSIRT coordinates the complete vulnerability management lifecycle, including:

  • Assessment and validation of reported vulnerabilities

  • Coordination with internal development and product teams

  • Development of remediation measures and security updates

  • Communication with affected customers and partners

  • Publication of security advisories and mitigation guidance

We recognize and value the contribution of security researchers, customers, partners, and independent experts. Through responsible and coordinated vulnerability disclosure, we continuously improve the security and resilience of our products

Coordinated Vulnerability Disclosure (CVD)

Tria Technologies supports the principles of Coordinated Vulnerability Disclosure (CVD).

We encourage security researchers and other stakeholders to report suspected vulnerabilities privately so that appropriate remediation measures can be developed before public disclosure.

Our objective is to:

  • Validate reported vulnerabilities promptly

  • Assess potential impact and affected products

  • Develop and test corrective actions

  • Inform affected stakeholders

  • Publish security advisories in a coordinated and transparent manner

We respectfully request that vulnerability details are not publicly disclosed until:

  • The issue has been investigated,

  • Appropriate safeguards or fixes are available, and

  • Coordinated publication has been agreed upon.

This approach helps ensure the protection of customers operating our products in industrial automation, critical infrastructure, transportation, medical, and other security-sensitive environments.

Report a Security Vulnerability

Reports regarding potential security vulnerabilities can be submitted to the Tria Technologies PSIRT regardless of whether an active customer relationship exists.

No NDA, support contract, or commercial agreement is required to submit a report.

Please contact us either in German or English language.

All vulnerability reports will be treated confidentially until public disclosure. We aim to coordinate the disclosure with the reporting party whenever feasible.

Contact Information

Please use our contact form: Contact PSIRT @ Tria Technologies

Or directly enter our ticket portal (Tria account required): https://tria-technologies.atlassian.net/servicedesk/customer/portal/36

Or contact us by email via Reveal email address

For encrypted communication, please use our PGP public key (see below).

Information Required for Efficient Investigation

To help us analyze and respond to your report as quickly as possible, please include the following information whenever available:

Contact Details

  • Name (optional)

  • Organization (optional)

  • Email address

  • Telephone number (optional)

Anonymous reports are welcome and will be handled with the same level of care and professionalism.

Vulnerability Description

Please provide:

  • A clear description of the vulnerability

  • Vulnerability type or category

    • Buffer Overflow

    • Cross-Site Scripting (XSS)

    • Authentication Bypass

    • Privilege Escalation

    • Remote Code Execution

    • Information Disclosure

    • Other

Reproduction Information

Please include:

  • Proof-of-Concept (PoC)

  • Step-by-step reproduction instructions

  • Log files

  • Screenshots

  • Network captures (PCAP)

  • Test scripts or tools used

Impact Assessment

Please describe:

  • Expected security impact

  • Potential attacker capabilities

  • Possible effects on confidentiality, integrity, and availability

Affected Products

Include:

  • Product name

  • Model number

  • Firmware version

  • Software version

  • Hardware revision (if applicable)

Disclosure Status

Please indicate:

  • Whether the vulnerability has been reported elsewhere

  • Any existing CVE assignment

  • Planned publication dates

  • Other affected vendors involved

Response Process

After receiving a report, our PSIRT follows a structured incident handling process.

Initial Acknowledgement

✓ Within 2 business days

Validation and Assessment

✓ Investigation and technical analysis

Remediation

✓ Development and testing of corrective actions

Coordinated Disclosure

✓ Publication of advisory and mitigation guidance

Target Remediation and Disclosure Timeline
Tria Technologies aims to investigate reported vulnerabilities, develop appropriate remediation measures, and coordinate public disclosure within 90 days of receiving a valid vulnerability report, whenever technically feasible. In cases where more extensive development, testing, or coordination with third-party suppliers is required, the timeline may be extended. The reporting party will be kept informed of significant progress throughout the process.

Safe Harbor Statement

Tria Technologies welcomes good-faith security research.

We will not pursue legal action against individuals who:

  • Act in good faith

  • Avoid privacy violations, service disruption, and data destruction

  • Do not exploit vulnerabilities beyond what is necessary for verification

  • Provide reasonable time for remediation before disclosure

Researchers are expected to comply with all applicable laws and to respect the privacy and security of our customers and partners.

Published Security Advisories

All security advisories issued by Tria Technologies PSIRT are available here.

Machine-Readable Security Information

security.txt

For automated discovery of our vulnerability disclosure information, Tria Technologies publishes a security.txt file in accordance with RFC 9116.

Location

https://security.tria-technologies.com/.well-known/security.txt

Secure Email Communication (PGP)

Given the sensitive nature of vulnerability information, Tria Technologies strongly recommends the use of encrypted communication.

Please use our public PGP key when sending vulnerability reports or other confidential security-related information.

PGP Information

Key ID: 0x17EC0B50382DBF9F

Fingerprint: AE48 3C18 561A 8950 D1E8 3DD7 17EC 0B50 382D BF9F

Public Key Download: https://security.tria-technologies.com/pgp/product.security@tria-technologies.com.asc

When contacting us for the first time, we recommend attaching your own public key to facilitate secure, end-to-end encrypted communication.

CSAF Security Advisories

To support automated vulnerability management processes, Tria Technologies plans to provide advisories in CSAF (Common Security Advisory Framework) format.

CSAF provider metadata: https://security.tria-technologies.com/.well-known/csaf/provider-metadata.json

Stay Informed

Subscribe to receive information about:

  • Security advisories

  • Product security updates

  • Vulnerability notifications

  • Critical remediation guidance

For questions regarding product security, please contact: Reveal email address

Contact Us