Genelec Vulnerability Disclosure Policy

Version: 1.0
Date: 11.9.2026


Our Commitment

Genelec is committed to the security of its products and services. We welcome responsible vulnerability reports from customers, partners, and security researchers to help us improve security and protect our users.


Scope

This policy covers security vulnerabilities affecting Genelec products and services, including hardware, firmware, software applications, cloud services, websites, APIs, network interfaces, update mechanisms, and related third-party components.


Responsible Security Research

Researchers should:

• Act lawfully and in good faith.
• Test only systems they own or are authorized to test.
• Minimize risks to users, services, and data.
• Immediately report exposure of sensitive information.
• Protect vulnerability information from unauthorized disclosure.
• Allow Genelec reasonable time to investigate and remediate issues before public disclosure.

Researchers must not:

• Disrupt services or perform denial-of-service testing.
• Access, modify, or delete other users' data.
• Use malware, phishing, social engineering, or credential attacks.
• Target Genelec customers, employees, partners, or facilities.
• Create safety risks or exploit vulnerabilities for personal gain.


How to report a vulnerability

Please send your report to security@genelec.com. Make sure to include as much of the following as you can:

• The affected product or service, including model, firmware or software version, or URL
• A description of the vulnerability and its type
• Its potential impact, and your view of its severity
• Step-by-step instructions to reproduce it
• Proof-of-concept code, screenshots, logs, or other supporting evidence
• Whether you are aware of the vulnerability being actively exploited

Do not submit sensitive data unless properly encrypted.
security.txt


What You Can Expect from Genelec

Genelec will:

• Acknowledge reports as soon as practical.
• Assess the severity and impact of reported vulnerabilities.
• Prioritize investigation and remediation based on risk.
• Coordinate with relevant internal and external stakeholders.
• Maintain communication with the reporter when contact details are provided.

Our goal is to address security issues responsibly, efficiently, and transparently.

www.genelec.com/privacy-policy


Coordinated disclosure

We ask that you do not publicly disclose a vulnerability until a fix or mitigation is available.


Information sharing

To resolve a vulnerability, we may share report details with suppliers of affected components. Where required by law, including the EU Cyber Resilience Act, we will also notify the relevant authorities, such as the designated national CSIRT and the European Union Agency for Cybersecurity (ENISA). We will not share your name or contact details with third parties without your permission, unless we have asked permission from you, or we are legally required to do so.


Changes to this policy

We may update this policy from time to time, and we review it at least once a year. The current version is always available at www.genelec.com/vulnerability-disclosure-policy