Scope

This policy covers hopit Edge — on Windows, Linux and as a container — together with the backend services required to operate it, such as license activation, device provisioning and update delivery. If you've found an issue affecting hopit Manufacturing, hopit Portal, or this website that isn't related to hopit Edge, please use the same contact below and we'll route it to the right team.

How to report a vulnerability

Email us directly:

security@heap-engineering.at

Please include:

  • the affected product and version
  • a description of the vulnerability and its potential impact
  • steps to reproduce it, or a proof of concept
  • any supporting logs, tools or screenshots
  • how you'd like to be credited, or if you'd prefer to stay anonymous

If you consider the details sensitive, say so in your first email and we'll agree on a secure channel before you send anything further.

What to expect from us

1

Confirmed instantly

You'll receive an automatic confirmation as soon as your report arrives.

2

Triaged within 2 days

A member of our security team reviews every report and aims to send an initial assessment within 2 business days.

3

Prioritized by risk

No single fixed deadline regardless of severity — critical and actively exploited issues are handled faster than routine reports. Active exploitation or a serious incident also triggers our notification obligations to the competent EU authorities under the Cyber Resilience Act.

4

Coordinated disclosure

We keep you updated as we investigate and remediate, and agree with you on when and how the issue is disclosed — normally once a fix or mitigation is available.

Reports that duplicate an issue already reported to us, or that don't describe a security vulnerability, are still read and acknowledged, but aren't tracked as part of this disclosure process.

Good-faith security research

We won't pursue legal action against security research carried out in good faith and in line with this policy: testing only against your own accounts or dedicated test systems, not accessing or modifying data that isn't yours, avoiding disruption to our services or our customers, and giving us a reasonable opportunity to investigate and remediate before any public disclosure. Social engineering, physical access attempts, and denial-of-service testing against production systems fall outside this policy.

Security advisories

Once a reported vulnerability has been fixed, we publish an advisory describing the issue, the affected versions, its severity, the fixed version or mitigation, and how to update. See Security Advisories.

Product support and updates

hopit Edge is licensed under a subscription model. Security updates are included at no additional cost for the duration of an active subscription. We're also finalizing a published minimum support and end-of-life policy for hopit Edge in line with the EU Cyber Resilience Act; subscribers will be notified in advance of any planned end-of-life for a supported release. Until that full policy is published here, support and end-of-life information for your specific release is available from your account contact.


This page describes HEAP Engineering's vulnerability reporting and disclosure process for hopit Edge. It does not constitute legal advice, a contractual commitment, or a complete statement of HEAP Engineering's obligations under the EU Cyber Resilience Act (Regulation (EU) 2024/2847) or any other applicable law.