Vulnerability disclosure policy

 


1. Introduction and Friulinox's commitment

Friulinox – Ali Group Srl ("Friulinox") places great importance on the security of its connected products and welcomes contributions from independent security researchers. This document describes how to responsibly report a suspected security vulnerability affecting Friulinox products, and what to expect from Friulinox once a report has been received.

This policy is also published in Italian; in the event of any discrepancy between the two versions, the Italian version shall prevail.

 

2. Scope

The following are in scope for this policy:

Friulinox devices equipped with Wi-Fi and/or cloud connectivity: Submarine, Ready Pro, Ready, Gravity, Breeze, Pure, Aroma, Vanilla, Paprika, and future connected products developed by Friulinox.

Friulinox digital infrastructure: web and cloud systems directly operated by Friulinox in support of these products (e.g. the friulinox.aftersalestools.com portal).

The following are out of scope for this policy:

Third-party services and components: services, components, or infrastructure of third parties not directly controlled by Friulinox, even where used in combination with Friulinox products.

Invasive or destructive testing: physical attacks on machines already installed at customer sites, social engineering against Friulinox staff, customers or distributors, and testing that causes denial of service on devices in active use by customers.

 

3. How to report a vulnerability

Reports can be submitted through:

Email: service@Friulinox.com — primary channel, available 24 hours a day, 7 days a week. Please include "Security Vulnerability Report – [product/model]" in the subject line.

Phone: +39 0434 635411 — for urgent reports involving potentially critical impact.

To allow a fast and effective assessment, please include in your report, as far as possible:

• the affected product/model and firmware/software version;

• a detailed description of the vulnerability and its potential impact;

• the steps needed to reproduce it (proof of concept, if available);

• a contact address for any follow-up questions.

Upon request, an encrypted communication channel can be arranged for sharing particularly sensitive information.

 

4. What to expect from Friulinox

Once a report is received, Friulinox is committed to following this process:

Stage

Indicative timeframe*

Acknowledgement of receipt

Within 5 business days

Initial assessment (triage) and severity scoring (CVSS v3.1)

Within 30 calendar days of receipt

Status updates, for confirmed reports still being worked on

At least every 30 days

Coordinated disclosure

Until a fix is available, or in any case no later than 90 days after the vulnerability is confirmed, unless otherwise agreed with the reporter

* These timeframes represent a reference commitment (in line with industry practice, cf. ISO/IEC 29147 and 30111) and may vary depending on the complexity of the case; the reporter is kept informed of progress regardless.

 

Vulnerabilities confirmed as actively exploited, or serious security incidents, are handled and — where required — notified to the competent authorities in accordance with Regulation (EU) 2024/2847 (Cyber Resilience Act), following Friulinox's internal vulnerability management process.

At the reporter's request, and where appropriate, Friulinox may publicly acknowledge the researcher's contribution in a security advisory. A paid bug bounty programme is not currently offered.

 

5. Commitment to good-faith reporters

Friulinox will not pursue legal action against anyone who reports a vulnerability in good faith and in accordance with this policy. Security researchers are asked to follow these guidelines:

• do not access, modify, or delete data beyond what is strictly necessary to demonstrate the existence of the vulnerability;

• do not conduct testing that could compromise the availability, integrity, or operational safety of devices in use at customer sites (Friulinox devices are professional foodservice equipment: testing must not interfere with their operation);

• do not exploit a vulnerability beyond what is necessary to confirm it, and avoid large-scale automated scanning that could impact Friulinox or customer systems;

• give Friulinox reasonable time to investigate and remediate the vulnerability before any public disclosure, consistent with Section 4;

• do not engage in social engineering, physical attacks, or denial-of-service testing.

 

6. Contact

Email: service@Friulinox.com

Phone: +39 0434 635411

Friulinox – Ali Group Srl, Via Treviso 4, Taiedo di Chions (PN), Italy

 

7. Policy updates

This policy is reviewed at least annually, or following relevant regulatory changes or significant changes to Friulinox's vulnerability management processes. Each newly published version carries its version number and effective date.