Landis+Gyr · Vulnerability Disclosure

Landis Gyr Vulnerability Disclosure

Vulnerability disclosure

Landis+Gyr runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

EnergyUnited StatesUtilitiesElectricityGasWaterSmart MeteringAMIGridGrid EdgeDemand ResponseInternet Of ThingsMeter Data ManagementWi-SUNEnergy Technology
Program: Hackerone

Disclosure Policy

Policy
Policy

Security Contact

Contact
productCERT@landisgyr.com
Contact
cybersecurity@landisgyr.com

Source

Vulnerability Disclosure

landis-gyr-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-27'
method: searched
probe: true
source: https://www.landisgyr.com/us/en/home/misc/report-security-issue
program:
  name: Landis+Gyr productCERT
  model: coordinated vulnerability disclosure
  scope: >-
    "a potential vulnerability has been associated to Landis+Gyr product or solution" —
    products, solutions and services. No scope exclusion list and no safe-harbour text is
    published.
  bug_bounty: false
  bug_bounty_note: >-
    No HackerOne, Bugcrowd or Intigriti programme was found. Disclosure is direct-to-vendor
    by email; no reward or bounty is offered or mentioned.
policy:
- https://www.landisgyr.com/us/en/home/misc/report-security-issue
- https://landisgyr.com/webfoo/wp-content/uploads/2024/11/Vulnerability-Management-Policy-Summary-v1.0.pdf
contact:
- productCERT@landisgyr.com
- cybersecurity@landisgyr.com
contact_roles:
- email: productCERT@landisgyr.com
  role: product vulnerability reports (primary)
- email: cybersecurity@landisgyr.com
  role: Global Cyber and Information Security team — general security topics
encryption:
  pgp: true
  key_url: https://landisgyr.com/webfoo/wp-content/uploads/2024/11/ProductCERT-Public.asc
  fingerprint: 345A B00A 110A 3543 0FF4 D2C2 6F7E 4510 C58E 79FC
  note: >-
    The page instructs reporters to use the PGP-protected channel for sensitive or
    confidential disclosures.
process:
  phases:
  - id: identification
    summary: >-
      Any person or organization may submit a report. Reporters state consent on whether
      their identity may be shared with Landis+Gyr partners and customers, or may remain
      anonymous. Receipt is acknowledged by the productCERT coordinator.
  - id: assessment
    summary: >-
      productCERT analyses the report, verifies the information and validates findings with
      the reporter. Assessment deliberately goes beyond the reported scope to find related
      problems in other products and services.
  - id: treatment
    summary: Published as a phase of the policy summary; remediation handling.
  - id: disclosure
    summary: Published as a phase of the policy summary; coordinated disclosure to partners and customers.
  acknowledgement: >-
    "Landis+Gyr will acknowledge receipt to all elevated submitted reports in a swift and
    transparent manner." No numeric SLA (hours/days) is published.
  quoted_principle: >-
    "Vulnerabilities exist. It is the question, how they are handled, that make the
    difference." — Landis+Gyr Security Team
evidence:
- source: https://www.landisgyr.com/us/en/home/misc/report-security-issue
  status: 200
  kind: disclosure-page
  keywords: [productCERT, coordinated vulnerability disclosure, PGP, security flaw, vulnerability management policy]
- source: https://landisgyr.com/webfoo/wp-content/uploads/2024/11/ProductCERT-Public.asc
  kind: pgp-public-key
- source: https://landisgyr.com/webfoo/wp-content/uploads/2024/11/Vulnerability-Management-Policy-Summary-v1.0.pdf
  kind: policy-document
not_found:
- /.well-known/security.txt on every resolving landisgyr.com host (404) — see well-known/landis-gyr-well-known.yml
- CVE / advisory publication feed
- bug bounty programme
- disclosure timeline commitment (e.g. 90 days)