Report a security vulnerability

CRIBWISE is part of Sandvik. We take the security of our products seriously, and we welcome reports from customers, partners and security researchers. If you believe you have found a security vulnerability in a CRIBWISE product or service, please tell us before disclosing it publicly, and we will work with you to confirm and address it.

Email cribwise-security@cribwise.com — this is our single point of contact for vulnerability reports and the fastest way to reach us. You can also use the form at the bottom of this page.

What to include

The more detail you can give us, the faster we can confirm and fix the issue. Where possible:

  • The affected product or component, and the version
  • A description of the vulnerability and its potential impact
  • Steps to reproduce it, including any preconditions
  • Whether you have any indication the vulnerability is being actively exploited
  • How you would like to be credited, if at all

Please do not attach working exploit code to the form. If you need to share files or evidence, email them to cribwise-security@cribwise.com instead.

Scope

In scope:

  • CRIBWISE Admin Portal (cloud)
  • CRIBWISE Shop Floor Interface (SFI), including on-premise deployments
  • CRIBWISE storage device integrations
  • The CRIBWISE public API
  • The cribwise.com website and its subdomains

Reports about third-party dependencies are welcome and will be forwarded to the relevant upstream project where appropriate.

Out of scope:

  • Third-party services and storage hardware we neither operate nor develop
  • Volumetric denial-of-service testing
  • Social engineering of Sandvik or CRIBWISE employees, and physical attacks
  • Findings from automated scanners with no demonstrated impact
  • Missing hardening headers or configuration preferences with no exploitable consequence

How reports are handled

After intake, each report is processed through a consistent vulnerability workflow:

  • Receive — the report is logged and tagged as a security issue.
  • Review — we assess applicability (is CRIBWISE affected?) and verifiability (can it be reproduced?).
  • Assess — we classify severity (CVSS), evaluate impact and exploitability, and determine remediation priority.
  • Address — we remediate, verify the fix, and coordinate disclosure timing.
  • Close and learn — we confirm closure and record lessons learned.

If a report concerns a third-party component, we coordinate with the relevant upstream maintainer in parallel with our own remediation planning.

Our commitment

StageTarget
Acknowledge receiptwithin 3 business days
Initial assessment & severity (CVSS)within 10 business days
Status updatesat least every 2 weeks until resolution
Fix & coordinated disclosuretimeline agreed with the reporter, prioritised by severity

Once a security update is available, we share information about the fixed vulnerability with affected customers, including a description, the affected products and versions, the impact, and what you need to do.

Safe harbour

We will not pursue or support legal action against anyone who, in good faith:

  • Makes a reasonable effort to report a vulnerability through the channel above,
  • Avoids privacy violations, data destruction and service degradation, and
  • Does not access or modify data beyond the minimum necessary to demonstrate the issue.

Activity conducted consistently with this policy is considered authorised. If in doubt, contact us at cribwise-security@cribwise.com before acting. Please also give us reasonable time to investigate and remediate before disclosing publicly, and coordinate the timing with us.

Supported versions and updates

Security updates are provided for supported releases during the product support period. Cloud deployments receive security updates automatically as part of our managed service. For on-premise deployments we make security updates available together with a clear description of their security relevance.

We do not operate a bug bounty

We do not currently offer monetary rewards for vulnerability reports. We are glad to credit reporters who want to be named.

Not a security issue?

For product questions, bugs without a security impact, or support requests, please use the Help Center or your usual support channel — those reach the right team faster.

Our security programme

Third-party penetration tests are performed on request and periodically, based on OWASP Top 10. Automated vulnerability scanning runs as part of our CI/CD pipeline on each deployment. Security work is aligned with the EU Cyber Resilience Act (CRA) programme, which is formalizing our vulnerability-management and testing cadence.

Submit a report

You can also email cribwise-security@cribwise.com directly. Name and email are optional — leave them blank to report anonymously.