generated: '2026-07-27' method: searched probe: true source: https://www.landisgyr.com/us/en/home/misc/report-security-issue program: name: Landis+Gyr productCERT model: coordinated vulnerability disclosure scope: >- "a potential vulnerability has been associated to Landis+Gyr product or solution" — products, solutions and services. No scope exclusion list and no safe-harbour text is published. bug_bounty: false bug_bounty_note: >- No HackerOne, Bugcrowd or Intigriti programme was found. Disclosure is direct-to-vendor by email; no reward or bounty is offered or mentioned. policy: - https://www.landisgyr.com/us/en/home/misc/report-security-issue - https://landisgyr.com/webfoo/wp-content/uploads/2024/11/Vulnerability-Management-Policy-Summary-v1.0.pdf contact: - productCERT@landisgyr.com - cybersecurity@landisgyr.com contact_roles: - email: productCERT@landisgyr.com role: product vulnerability reports (primary) - email: cybersecurity@landisgyr.com role: Global Cyber and Information Security team — general security topics encryption: pgp: true key_url: https://landisgyr.com/webfoo/wp-content/uploads/2024/11/ProductCERT-Public.asc fingerprint: 345A B00A 110A 3543 0FF4 D2C2 6F7E 4510 C58E 79FC note: >- The page instructs reporters to use the PGP-protected channel for sensitive or confidential disclosures. process: phases: - id: identification summary: >- Any person or organization may submit a report. Reporters state consent on whether their identity may be shared with Landis+Gyr partners and customers, or may remain anonymous. Receipt is acknowledged by the productCERT coordinator. - id: assessment summary: >- productCERT analyses the report, verifies the information and validates findings with the reporter. Assessment deliberately goes beyond the reported scope to find related problems in other products and services. - id: treatment summary: Published as a phase of the policy summary; remediation handling. - id: disclosure summary: Published as a phase of the policy summary; coordinated disclosure to partners and customers. acknowledgement: >- "Landis+Gyr will acknowledge receipt to all elevated submitted reports in a swift and transparent manner." No numeric SLA (hours/days) is published. quoted_principle: >- "Vulnerabilities exist. It is the question, how they are handled, that make the difference." — Landis+Gyr Security Team evidence: - source: https://www.landisgyr.com/us/en/home/misc/report-security-issue status: 200 kind: disclosure-page keywords: [productCERT, coordinated vulnerability disclosure, PGP, security flaw, vulnerability management policy] - source: https://landisgyr.com/webfoo/wp-content/uploads/2024/11/ProductCERT-Public.asc kind: pgp-public-key - source: https://landisgyr.com/webfoo/wp-content/uploads/2024/11/Vulnerability-Management-Policy-Summary-v1.0.pdf kind: policy-document not_found: - /.well-known/security.txt on every resolving landisgyr.com host (404) — see well-known/landis-gyr-well-known.yml - CVE / advisory publication feed - bug bounty programme - disclosure timeline commitment (e.g. 90 days)