Skip to main content

Title

Les sociétés d’exploitation de la famille Duravant desservent les secteurs de la transformation alimentaire, de l’emballage et de la manutention.

The Duravant family of operating companies serve the food processing, packaging and material handling segments.

POL-CYB-01 Coordinated Vulnerability Disclosure Policy

Purpose

Multiscan Technologies is committed to maintaining the security of its products and encourages the responsible reporting of potential cybersecurity vulnerabilities. This policy defines how vulnerabilities affecting Multiscan products can be reported and how such reports will be handled.

Scope

This policy applies to:

This policy applies to vulnerabilities that may affect the cybersecurity of Multiscan products with digital elements, including software developed by Multiscan and digital or software components integrated into Multiscan products where such components may affect the cybersecurity of the product.

This policy does not apply to:

• General technical support requests.
• Product complaints unrelated to cybersecurity.
• Commercial enquiries.

Reports concerning cybersecurity incidents may also be received through the same contact channel and will be handled through the appropriate internal processes.

Reporting a Vulnerability

Multiscan designates cybersecurity@multiscan.eu as its single cybersecurity contact point for reporting and receiving information about potential product cybersecurity vulnerabilities. This contact point is maintained by Multiscan and is intended to allow direct communication regarding product cybersecurity matters.

When possible, reports should include:

• Product name.
• Product version.
• Description of the vulnerability.
• Steps required to reproduce the issue.
• Potential impact.
• Supporting evidence or screenshots.

Incomplete reports may require additional information before assessment can begin.

Vulnerabilities may also be reported through competent CSIRT channels where such channels are available under applicable EU or national coordinated vulnerability disclosure frameworks.

Coordinated Disclosure Principles

Multiscan will:

• Register reported vulnerabilities.
• Perform an initial assessment.
• Conduct a technical investigation when appropriate.
• Determine whether the reported issue affects Multiscan products.
• Define corrective or mitigation actions when required.
• Maintain appropriate records of the report, assessment, decisions taken and corrective or mitigation actions.

Reports are handled according to the internal cybersecurity management processes established by Multiscan.

Multiscan may contact the reporter when additional information is required to support the assessment and investigation process.

The receipt or confirmation of a vulnerability does not automatically imply regulatory notification or public disclosure. Where applicable, Multiscan will assess whether regulatory notification, user communication or coordinated disclosure activities are required.

Multiscan will seek to coordinate vulnerability handling in a manner that supports diagnosis and remediation before detailed technical information is disclosed to third parties or to the public, where appropriate.

Expectations for Reporters

Individuals reporting vulnerabilities are expected to:

• Act responsibly and in good faith.
• Avoid actions that may disrupt customer operations.
• Avoid accessing, modifying or deleting data that does not belong to them.
• Avoid actions that could affect the availability or integrity of systems.
• Respect applicable laws and contractual obligations.

Handling of Reported Vulnerabilities

The vulnerability handling process generally consists of:

Receipt of the report.
Initial assessment.
Technical investigation, when appropriate.
Determination of applicability to Multiscan products.
Definition of corrective or mitigation actions, where applicable.
Assessment of whether regulatory notification or user communication is required.
Closure and documentation.

Where appropriate, Multiscan may provide information to affected users regarding available corrective or mitigation measures.

Where required by applicable regulations, additional evaluation, notification or communication activities may be performed according to Multiscan internal procedures.

Confidentiality

Information provided during the vulnerability reporting process will be handled according to Multiscan internal processes and applicable legal obligations.

Multiscan may request additional information from the reporter when necessary to facilitate assessment and investigation.

Multiscan will seek to avoid premature disclosure of vulnerability details before appropriate corrective or mitigation measures have been assessed.

Contact Information

Cybersecurity Contact Point

Multiscan Technologies

cybersecurity@multiscan.eu

Multiscan appreciates responsible vulnerability reporting and will review all reports received through the established cybersecurity contact point.