We treat the security of our products as a core part of their quality. As a manufacturer of software and hardware with digital elements under Regulation (EU) 2024/2847 (Cyber Resilience Act, CRA), we operate a coordinated vulnerability disclosure (CVD) policy. We encourage security researchers, customers, integrators and partners to report any weaknesses they find.
This policy covers:
- the GEMOS PSIM / SIUP platform, its interfaces and components,
- the FPM+ (Fire Protection Manager) panel and its software,
- other software and firmware supplied by Ela-compil,
- the ela.pl, gemos.pl, portal.gemos.pl and firematrix.pl websites.
How to report a vulnerability
The single point of contact for vulnerabilities is . You can use the form below, which prepares a message in your mail client, or write to us directly. You may also submit a report through CERT Polska, the national coordinator for vulnerability disclosure in Poland.
Manufacturer: Ela-compil sp. z o. o., ul. Szczepanowskiego 8, 60-541 Poznań, Poland, ela.pl. We do not run a bug bounty programme and do not pay rewards for reports.
Please encrypt sensitive details, in particular proof-of-concept code, with our PGP public key (fingerprint: 5A99 190A 1EF3 9977 ACED 424B 7FD9 1EE2 778C 9AF5, also available on keys.openpgp.org). We accept reports in English and Polish. Our machine-readable contact details are published in security.txt according to RFC 9116.
What to include
The more precise the report, the faster we can confirm and fix the issue. Please provide:
- the product and version (version number, firmware release, or URL for the website),
- a description of the vulnerability and its potential impact,
- steps to reproduce, ideally with proof-of-concept code, logs or screenshots,
- whether the vulnerability has already been disclosed anywhere,
- contact details for follow-up (optional). Personal data is not required and we also handle anonymous reports.
What we do with your report
- Acknowledgement of receipt within 5 working days.
- Analysis and triage of the vulnerability (including CVSS scoring) and feedback on our initial assessment.
- Remediation. Our target is to release a fix or mitigation within 90 days of confirmation. Critical vulnerabilities are prioritised. If the deadline cannot be met, we inform the reporter and explain why.
- Publication of a security advisory once the fix is available, at a date agreed with the reporter. The advisory describes the vulnerability, the affected products and versions, its impact and severity, and instructions to remediate or mitigate it. We request a CVE identifier for confirmed vulnerabilities.
- Credit to the reporter in the advisory, if they wish.
In line with Article 14 of the CRA, we report actively exploited vulnerabilities and severe incidents affecting the security of our products through the ENISA Single Reporting Platform to the competent CSIRT: an early warning within 24 hours, a notification within 72 hours, followed by a final report. We inform affected users without undue delay, where necessary together with recommended corrective or mitigating measures.
Rules of engagement and safe harbour
We will not pursue legal action against anyone who researches the security of our products in good faith and follows these rules:
- do not exploit a vulnerability beyond what is necessary to demonstrate it,
- do not access, modify or delete data that does not belong to you,
- do not perform denial-of-service, social-engineering or physical attacks,
- do not test systems belonging to Ela-compil customers without the owner’s consent,
- do not disclose the vulnerability publicly before the date agreed with us,
- comply with applicable law.
Exclusions and limitations
The following are not considered vulnerabilities under this policy:
- output of automated scanners without a confirmed, reproducible security impact,
- vulnerabilities in products that have reached the end of their support period. We still accept and assess such reports, including against our notification obligations, but remediation may be limited to guidance for users,
- vulnerabilities in standalone third-party products that are not part of our products (we forward such reports to the relevant vendor). Vulnerabilities in third-party components and open-source libraries embedded in GEMOS or FPM+ are in scope and handled like our own,
- best-practice recommendations without direct security impact (for example missing HTTP headers on the informational website).
Security support
For supported versions of our products we provide security updates throughout the support period, free of charge, together with advisories describing the fixed vulnerability and the recommended user actions. Where technically feasible, security updates are delivered separately from functional updates. The support period and its end date are stated in the documentation of each product and version.
Personal data and changes to this policy
Contact details of reporters are processed solely to handle the report, in line with our privacy policy. This policy may be updated; the current version is always available at this address. Last updated: 4 September 2026.