Report a security vulnerability
The security of our products is a priority throughout their entire lifecycle.
If you have identified a potential vulnerability or cyber security incident affecting a Salvagnini product, please contact our Product Security Incident Response Team. The information you provide will help us investigate the issue and determine the most appropriate actions.
The Salvagnini Product Security Incident Response Team
The Product Security Incident Response Team, PSIRT, is Salvagnini’s dedicated point of contact for handling cyber security reports concerning products with digital elements.
The team brings together specialists from our Cyber R&D department and coordinates the investigation of potential vulnerabilities or incidents that could affect the confidentiality, integrity or availability of Salvagnini products and industrial solutions.
The PSIRT supports product security throughout the entire product lifecycle. It handles the information received confidentially and works with the relevant internal teams to identify appropriate mitigation measures or corrective actions.

How do we handle your report
- Receipt and initial assessment
We verify that the report concerns the cyber security of a Salvagnini product and review the information available. - Technical investigation
Our team investigates the issue to assess its validity, relevance and reproducibility. During this phase, we may contact you to request additional information or technical evidence. In compliance with European regulations, should it be determined that the report involves an actively exploited vulnerability or a severe incident, we will notify the designated European bodies within 24 hours. - Mitigation and remediation
Based on the outcome of the investigation, we determine the most appropriate course of action. This may include operational guidance, mitigation measures, technical actions or the development of a corrective update. - Communication and regulatory obligations
Where appropriate, we provide the reporter with the information needed to manage the issue securely. We also submit any required notifications to the relevant authorities and bodies, in accordance with the timelines and procedures established by applicable regulations.
What information to include
To help us assess your report as effectively as possible, please include any available information from the sections below.
Product identification
- Product name and model
- Machine serial number, if applicable
- Affected software or firmware version
Issue description
- A technical description of the potential vulnerability or incident
- Technical evidence (log files, screenshots, error messages, network traffic captures, or other evidence, if available)
- The steps required to reproduce the issue, if available
Impact assessment and context:
- Potential impact on machine availability
- Potential impact on data confidentiality
- Potential impact on data integrity or process control
- Any potential implications for human safety
- Details of the operating environment, such as network isolation, remote access or firewall configuration
- Any known exploitation attempts or ongoing attacks
You can still submit a report if some of this information is not available. Please provide as much relevant detail as possible.
Reports submitted through this channel should concern potential cyber security vulnerabilities or incidents affecting Salvagnini products.
For technical support, maintenance or operational issues unrelated to cyber security, please use the standard Salvagnini support channels.
The information provided will be used to investigate and manage the report in accordance with the applicable corporate procedures.