We are committed to ensuring the cybersecurity of our products with digital elements throughout their lifecycle. As required by the EU Cyber Resilience Act (CRA), we have established a Coordinated Vulnerability Disclosure (CVD) policy that enables security researchers, customers, and other stakeholders to responsibly report potential vulnerabilities.

This page explains how to report vulnerabilities, what information to include, and how we handle and disclose reported issues. Our goal is to foster transparent and responsible collaboration, ensuring that vulnerabilities are addressed efficiently and that affected users are protected in a timely manner.

We encourage anyone who identifies a potential security issue in our products to report it as soon as possible through the channels described below and to act in good faith in accordance with this policy.

This policy is aligned with the principles of ISO/IEC 29147 (Vulnerability Disclosure) and ISO/IEC 30111 (Vulnerability Handling Processes).


Contact channel

To report a potential security vulnerability, please use the following dedicated channels:

Email (primary channel):

A dedicated reporting address is provided via our security.txt file: security@infors-ht.com, deployed at https://infors-ht.com/.well-known/security.txt. This inbox is actively monitored during regular business hours, and we aim to acknowledge all valid reports within a reasonable timeframe.

Telephone (urgent cases only):

For severe or seemingly actively exploited vulnerabilities that require immediate attention outside of business hours, the telephone contact +41 61 425 77 00 is available. This channel should be used only for urgent incidents where delayed handling could significantly increase risk.


Reporting instructions

When submitting a report, provide sufficient information to enable analysis and reproduction where possible, including:

  • Product name, version, and affected component(s)
  • Description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Technical details, logs, screenshots, proof-of-concept material, or any other supporting evidence where available
  • Information about the environment in which the issue was observed
  • Your contact details for follow-up communication

Please do not publicly disclose vulnerability details before remediation actions or coordinated disclosure activities have been completed.


Scope (products)

All Infors products currently under support are “products with digital elements”, according to the definition of the EU Cyber Resilience Act (CRA), where Infors is identified as a “manufacturer of products”:

  • Shakers
    • Minitron
    • Multitron
    • Multitron Standard
    • Celltron
  • Bioreactors
    • Minifors
    • Multifors
    • Labfors
    • Techfors-S
    • Techfors
  • Software
    • eve


Response and handling expectations

Upon receipt of a report, and in accordance with CRA obligations, we will work with the reporter to:

  • Acknowledge receipt of the vulnerability report within 5 business days.
  • Assess the potential vulnerability or incident (triage and second feedback) in a reasonable timeframe.
  • Prioritize and handle confirmed vulnerabilities and incidents according to their severity, active exploitation, exploitability and impact.
  • Communicate with you directly through the CVD process, when contact details are available and where appropriate, including for disclosure coordination.
  • Send at least a final feedback including details about the resolution of the vulnerability or incident.


This timeline does not affect our obligation to take any immediate actions required under the CRA, including timely notification to relevant authorities where applicable.


Coordinated disclosure rules

We follow a CVD process workflow including a coordinated approach to vulnerability disclosure to ensure that security issues are addressed effectively while minimizing risks for users. These rules, in line with regulatory obligations, ensure a balanced approach between transparency, responsible handling, and the protection of users and systems.

  • Coordination with the reporter: We will work with the reporter to assess the vulnerability and agree on an appropriate timeline for remediation and disclosure.
  • Confidentiality: We commit to protect the confidentiality of sensitive information throughout the process, including: the identity of a reporter who would wish to remain anonymous, any information regarding a specific customer that would have been compromised by a vulnerability or incident, and by restricting access by Infors organizational units on a “need-to-know” basis.
  • Remediation before public disclosure: As a general rule, we will publicly disclose vulnerabilities after or along with a fix or mitigating measures, unless earlier disclosure is necessary to reduce immediate risk or impact.
  • Disclosure timeline: We diligently work on resolving vulnerabilities within a reasonable timeframe. If remediation is delayed, we may coordinate with the reporter on a revised disclosure timeline that balances transparency with user protection.
  • User communication: Once a fix is available, we will inform affected users through appropriate channels (e.g., security advisories or release notes), including relevant details and recommended actions.
  • Exceptions to coordinated disclosure: In exceptional cases, such as active exploitation or significant risk to users, we may accelerate disclosure or take additional measures in line with regulatory obligations.


Safe harbor statement

We support and encourage responsible security research conducted in good faith. If you act in accordance with this policy when identifying and reporting vulnerabilities, we commit to not pursuing legal action against you for your research activities.

In particular:

  • Authorized testing: Activities such as testing, probing, or analyzing our products for vulnerabilities are permitted, provided they are carried out responsibly and do not negatively impact the confidentiality, integrity, or availability of our systems.
  • Good-faith reporting: You must make a genuine effort to avoid privacy violations, service disruption, or data destruction, and promptly report any identified vulnerability through the designated channels.
  • No exploitation: Vulnerabilities must not be exploited beyond what is necessary to demonstrate their existence and must not be used for personal gain or to harm others.
  • Confidentiality: You agree not to publicly disclose vulnerability details until we have had a reasonable opportunity to investigate and remediate the issue, in line with our coordinated disclosure rules.


We consider activities conducted under these conditions to be authorized and will treat them as such.


High-level handling workflow

We handle all reported potential vulnerabilities or incidents through a formal process, including a Coordinated Vulnerability Disclosure (CVD) workflow, to ensure consistent, timely, and CRA-compliant treatment.

The key steps of this process are:

  • Receipt and acknowledgement: All reports are logged and acknowledged, ensuring traceability and timely initial response.
  • Initial assessment and triage: Reports are assessed and classified, including distinguishing between general cybersecurity topics and CRA-relevant vulnerabilities or incidents affecting Infors products.
  • Validation and risk evaluation: Confirmed vulnerabilities are analyzed to determine their validity, scope, and severity.
  • Regulatory compliance handling: The process includes explicit steps and control gates to ensure compliance with CRA obligations, including applicable timelines and reporting to ENISA.
  • Remediation and integration: Vulnerabilities are addressed through established internal processes for non-conformity handling and are integrated into product development, maintenance, and release workflows.
  • Coordination and communication: Where applicable, we coordinate with the reporter and ensure appropriate internal and external communication throughout the handling process.
  • Documentation and controlled disclosure: All steps are systematically documented, with defined control points and structured information disclosure aligned with coordinated disclosure principles.
  • Closure and continuous improvement: Cases are formally closed once resolved, including a structured lessons-learned review to improve products and processes.