×
Back

Product Security / EU Cyber Resilience Act (CRA)

1. Purpose of this Notice

Axioma Metering is committed to maintaining the cybersecurity of its products and services and to working with security researchers, customers and partners who responsibly report potential vulnerabilities.

This page explains how to report a potential security vulnerability, which Axioma Metering products and services are covered by our coordinated vulnerability disclosure process, and what to expect after submitting a report.

2. Scope

In scope:

  • Axioma Metering smart water meters and smart heat meters, including device firmware and communication interfaces;

  • the AxiLink mobile application;

  • the AxiReach remote device management platform;

  • publicly accessible Axioma Metering websites and customer portals directly operated by Axioma Metering.

Out of scope are third-party systems or infrastructure not controlled by Axioma Metering, social engineering and phishing, DoS/DDoS testing, testing of devices that the researcher does not lawfully control, and attempts to access data belonging to other persons.

3. How to Report a Vulnerability

Registered Axioma Metering customers and partners can submit reports through the Axioma Metering Service Desk by selecting a product and “Reason” value “Cyber Security Vulnerability”: Report a vulnerability via Service Desk.

Security researchers and other parties who do not have access to the Service Desk can report vulnerabilities by email to security@axioma.eu.

Encrypted communication is recommended when sending sensitive information. The PGP public-key link is provided on this page: https://www.axiomametering.com/security/axioma-security-public-key.asc.

Where possible, please include:

  • the affected product and, if known, its version or firmware number;

  • a detailed description of the vulnerability;

  • steps to reproduce it;

  • the potential impact;

  • where applicable, a proof of concept with sensitive third-party data removed.

4. What to Expect

  • We will acknowledge receipt within 5 business days.

  • We will provide an initial assessment of validity and severity within 10 business days.

  • We will provide status updates at least every 30 days while the vulnerability remains under remediation.

  • We will coordinate the public disclosure timeline with the researcher, generally up to 90 days from acknowledgement. This period may be extended where remediation is complex or shortened where a vulnerability is actively exploited.

5. Good-Faith Research

Axioma Metering will not pursue legal action against researchers who act in good faith and comply with these conditions:

  • do not violate privacy, destroy or modify other persons’ data, or disrupt service delivery;

  • report a discovered vulnerability to Axioma Metering as soon as reasonably possible;

  • do not exploit the vulnerability beyond what is necessary to demonstrate its existence;

  • do not publicly disclose information before the agreed coordinated disclosure date;

  • comply with applicable law and third-party rights.

6. Rules of Engagement

  • Before running automated scanning that could disrupt service delivery, contact us in advance at security@axioma.eu.

  • Do not access, modify or delete data belonging to other persons.

  • Limit any proof of concept to the minimum necessary to demonstrate the vulnerability.

  • Do not use a discovered vulnerability for any purpose other than reporting it to Axioma Metering.

7. Recognition and Bug Bounty

At its discretion and with the researcher’s consent, Axioma Metering may publicly acknowledge researchers who contribute to product security.

Axioma Metering does not currently offer a paid bug bounty programme.

8. Security Advisories

Information about fixed product-security vulnerabilities and, where applicable, related security updates will be published on this page.

There are currently no published security advisories.

9. Contact and Changes to this Notice

Vulnerability reports: security@axioma.eu

General questions about CRA or this process: cra@axioma.eu

Axioma Metering may update this notice to reflect regulatory developments, product changes, technical implementation changes or updates to its vulnerability-handling process. The latest version will be published on this page.

This notice is based on the Axioma Metering Coordinated Vulnerability Disclosure (CVD) Policy and Regulation (EU) 2024/2847, the EU Cyber Resilience Act (CRA).

To improve your browsing experience on this website, we use cookies. By clicking on the "I Accept" button or by browsing further, you confirm your acceptance of the cookie installation. For more information on cookies, see Privacy Policy.