generated: '2026-08-17' method: searched source: https://www.selectron.ch/en/services-and-support/cybersecurity-services/ probe: false probe_note: >- 0-working/probe-security-programs.py returned vdp=none for selectron — Selectron serves no /.well-known/security.txt and no page at the conventional /security, /responsible-disclosure or /vulnerability-disclosure paths. The reporting address below was found by reading the Cybersecurity Services page directly and is quoted verbatim from that page's mailto link. policy: [] policy_note: >- No written responsible-disclosure or coordinated-vulnerability-disclosure policy, bug bounty program, PSIRT advisory feed or CVE/CSAF publication was found on any public Selectron surface. A dedicated product-security reporting mailbox is published, which is the intake channel without the surrounding policy. contact: - product_security_reporting@selectron.ch contact_context: 'Published on the Cybersecurity Services page under the heading "Product Security Selectron:"' security_txt: false bug_bounty: false evidence: - source: https://www.selectron.ch/en/services-and-support/cybersecurity-services/ http_status: 200 kind: product-security-contact quote: 'Product Security Selectron: product_security_reporting@selectron.ch' - source: https://www.selectron.ch/.well-known/security.txt http_status: 404 kind: security.txt-absent x-context: >- Selectron ships rail cybersecurity products (Security Gateway, Threat Detection Solution) and sells IEC 62443 and EU Cyber Resilience Act consulting, so a named product-security intake is consistent with its own offering. Under the CRA, a coordinated vulnerability disclosure policy becomes an obligation for products with digital elements — publishing one, plus an RFC 9116 security.txt pointing at it, is the obvious next step for this provider.