Skip to content
  • There are no suggestions because the search field is empty.
Close
  • Products
  • Services
  • Applications
  • Resources
  • Company
  • Support
  • FAQ
  • News & Announcements
  • Careers
  • About
  • In-Situ.com

Product Security & Coordinated Vulnerability Disclosure (CVD) Process

This Product Security & Coordinated Vulnerability Disclosure Process ("CVD Process") applies to the OTT HydroMet and In-Situ legal entities identified in Annex 1 below (each a "Responsible Entity"). For purposes of this CVD Process, the Responsible Entity is the legal entity identified in Annex 1 that is responsible for the affected product or service. The Responsible Entity is committed to improving the security of its products and services and to facilitating the responsible reporting of potential cybersecurity vulnerabilities. To support these efforts, the Responsible Entity maintains this CVD Process through which customers and other parties may report potential vulnerabilities.

Scope

This CVD process is intended solely for the reporting of potential cybersecurity vulnerabilities relating to products and services for which the Responsible Entity is the manufacturer or responsible provider. This process is not a customer support channel and should not be used for general product inquiries, warranty claims, service requests or other non-security-related matters. Such matters should be submitted through the relevant customer support, privacy, or other designated contact channel.

Contact information and CVD submission process

Potential security vulnerabilities relating to products and services for which the Responsible Entity is the manufacturer or responsible provider may be reported to productsecurity@ott.com using the PGP public key. Use of the PGP public key is recommended where the report contains security-sensitive technical information.

Submitters should not provide passwords, authentication credentials, unnecessary personal data, or other information that they are not authorized to disclose. Where supporting materials are necessary to investigate a reported vulnerability, submitters should minimize, redact or anonymize sensitive information where reasonably practicable and use the submission method identified above.

To the extent available and relevant, submitter should provide the following information:

  • Contact details through which the Responsible Entity may communicate with you, unless you elect to report anonymously Date and method of discovery
  • Description of potential vulnerability
  • Product name
  • Version number
  • Configuration details
  • Steps that may allow the Responsible Entity to reproduce the reported issue
  • Tools and methods
  • Exploitation code
  • Privileges required
  • Observed or reasonably anticipated impact

Submitter should not provide any information, code or materials that they are not authorized or otherwise legally entitled to possess, use or disclose.

What happens next

Upon receipt of a potential product vulnerability submission, the Responsible Entity may, as appropriate, having regard to the nature and content of the report:

    • Use reasonable efforts to acknowledge receipt of the submission, typically within five (5) business days
    • Conduct an initial assessment of the reported information
    • Contact the submitter for additional information where reasonably necessary to assess the report
    • Assess whether the reported issue affects an in-scope product or service
    • Triage and prioritize a validated vulnerability having regard to the relevant risks and applicable legal requirements
    • Coordinate communications concerning the vulnerability with the submitter and other relevant parties, where appropriate
    • Take such further measures as the Responsible Entity considers appropriate or as required by applicable law

The Responsible Entity may be unable to evaluate a report if the information provided is incomplete, inaccurate, unverifiable, outside the scope of this CVD Process or does not permit the reported issue to be reproduced. Any information provided regarding the status, assessment or anticipated handling of a report is preliminary, may change as the investigation progresses and does not constitute a commitment regarding validation, remediation, publication or timing.

Use of submitted information and privacy

The Responsible Entity and its affiliated companies, service providers and professional advisers may use and share information submitted under this CVD Process to receive, assess, investigate, validate, prioritize, remediate, document, communicate or otherwise respond to the reported issue; comply with legal and regulatory obligations; protect products, systems, customers and users; and coordinate with affected suppliers, customers, researchers, authorities, or other relevant parties, in each case as appropriate and subject to applicable law.

Personal data submitted through this CVD Process will be processed by the Responsible Entity for the affected product or service and, where relevant, by its affiliated companies involved in the assessment, investigation and handling of the reported vulnerability, in accordance with the applicable privacy policy on the Responsible Entity website notice.

Disclaimer

Submission of a report does not entitle the submitter to compensation, reimbursement, recognition, a particular response, access to investigation materials, or any other benefit unless expressly stated otherwise in writing.

Security testing may adversely affect the availability, integrity, safety, performance, warranty status or regulatory status of a product or system. Testing must not be performed on products used in production, safety-critical, customer, operational or other live environments. Products subjected to security testing should be appropriately isolated and assessed before any subsequent use. The Responsible Entity may modify this process from time to time. The version available on this webpage at the time a report is submitted will apply to that report, subject to applicable law.

The Responsible Entity will assess and handle reports in accordance with its applicable processes and legal obligations. The nature, priority, timing and extent of any investigation, remediation, update, communication or disclosure will depend on the circumstances, including the information available, technical feasibility, affected products, associated risks and applicable legal requirements. Except where required by applicable law, this process does not create any commitment to undertake a particular measure or to do so within a particular period.

The Responsible Entity does not guarantee that it will be able to verify, reproduce or remediate every reported issue. Any acknowledgement or communication from the Responsible Entity does not constitute acceptance that a vulnerability exists or that the Responsible Entity has any liability in relation to the reported issue. To the maximum extent permitted by applicable law, the Responsible Entity is not responsible for costs or expenses incurred by a submitter in connection with research, testing, reporting or participation in this process.

***

Annex 1 – List of Responsible Entities

  1. Ott Hydromet GmbH
    Ludwigstrasse 16
    87437 Kempten
    Germany
  2. Ott Hydromet Corp.
    22400 Davis Drive, Suite 100
    Sterling, Virginia 20164
    USA
  3. In-Situ, Inc.
    221 East Lincoln Avenue
    Fort Collins, Colorado 80524
    USA
  4. In-Situ Europe Ltd.
    Unit 24 Thornhill Road
    North Moons Moat
    Redditch, Worcs. B98 9ND
    United Kingdom
  5. Ott HydroMet Ltd.
    19 Jessops Riverside
    800 Brightside Lane
    Sheffield S9 2RX
    United Kingdom
  6. Partech Ltd.
    Rockhill Business Park, Higher Bugle
    St. Austell, Cornwall PL26 8RA
    United Kingdom
  7. Measuring and Control Equipment Pty Ltd (MACE)
    Unit 19 / 276 New Line Road
    Dural, NSW 2158
    Australia
  8. Ott HydroMet SARL
    Immeuble le Clamar - Bat B
    240 rue Rene Descartes - CS 10395
    13799 Aix-en-Provence Cedex 3
    France
  9. In-Situ Monitoring Asia Pte Ltd
    1 Gateway Drive, #07-01
    Westgate Tower
    Singapore 608531