MACHEREY-NAGEL Product Security
At MACHEREY-NAGEL, the security of our products and software solutions is our highest priority. Despite comprehensive quality assurance and security measures, vulnerabilities can never be completely ruled out.
This means that, as of 11 September 2026, all incidents must be reported within the legally prescribed timeframes via the central platform of the European Union Agency for Cybersecurity (ENISA) (https://www.enisa.europa.eu/) using the Single Reporting Platform (SRP) (https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp).
We welcome reports from customers, users, security researchers, and partners that help us continuously improve the security of our products.
Reporting a Security Vulnerability
If you have discovered a potential security vulnerability in a MACHEREY-NAGEL product, software application, or online service, please contact us at:
Please provide the following information whenever possible:
- Name of the affected product
- Software or firmware version
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Screenshots or log files (if available)
- Contact information for follow-up questions
The Product Security Incident Response Team (PSIRT) of MACHEREY-NAGEL (MN) is responsible for the assessment and disclosure of security vulnerabilities related to both hardware and software products. All reports of potential vulnerabilities or other security incidents concerning MN devices can be submitted to the MN PSIRT via email at: psirt@mn-net.com. The MN PSIRT coordinates and maintains communication with all relevant stakeholders, both internally and externally, to ensure an appropriate response to identified security issues.
Responsible Disclosure
We kindly ask that you:
- Treat security vulnerabilities confidentially.
- Do not publicly disclose information before sufficient time has been provided to resolve the issue.
- Do not modify, delete, or disclose customer or third-party data.
- Do not perform Denial-of-Service (DoS/DDoS) attacks.
- Do not use social engineering techniques.