Skip to main content Scroll Top

Security

Reporting a security vulnerability to EMRI

EMRI builds control and navigation equipment for ships. If you believe you have found a security vulnerability in one of our products or on our website, we want to hear about it. We welcome reports made in good faith, we will work with you to understand and fix the issue, and we will not take legal action against research that follows this policy.

Published security advisories

When we fix a security vulnerability in one of our products, we publish a security advisory: what the flaw is, which product versions are affected, and what you should do about it. Advisories are public — you do not need an account, a login or a support contract to read one.

Advisories are listed at emri.dk/security/advisories, grouped by product. Each advisory keeps a permanent link containing its identifier, so you can cite it, bookmark it, or record it in a vessel maintenance log. We amend advisories in place rather than republishing them, and we do not remove them once published.

You can also be notified by email when a security vulnerability is found in an EMRI product you use. Register the products you are interested in at emri.dk/security/sign-up — no account is needed.

Scope

This policy covers:

  • EMRI products that contain digital elements and are within their declared security-support period
  • Reports concerning other EMRI products and the emri.dk website are also accepted and assessed on a best-effort basis

Do not test equipment that is installed on a vessel in service. See Rules for good-faith research below.

How to report

  • Preferred: use our report form. No account is needed, and you can report anonymously.
  • Email: security@emri.dk

We do not currently offer a PGP key. If your finding is too sensitive for plain email, send a short summary without the technical details and we will arrange a secure channel with you.

What to include

  • The product and, if known, the software version
  • A description of the vulnerability, with the steps to reproduce it
  • The impact you observed or expect
  • Optionally, your name and an email address for follow-up

If you believe an actively exploited vulnerability or a cybersecurity incident is affecting EMRI products in the field, please indicate this in your report so we can prioritise handling.

Anonymous reports are accepted, but without contact details we cannot acknowledge your report or keep you informed.

What you can expect from us

  1. We acknowledge your report within 2 business days and give you a reference number.
  2. We give you an initial assessment within 5 business days: we assess whether the reported issue constitutes a cybersecurity vulnerability and whether EMRI products are affected.
  3. Where appropriate, we develop and make available security updates, mitigations or operational guidance to affected customers.
  4. We keep you informed while your report is open, and we tell you when a fix or mitigation is released.
  5. When we publish a security advisory for the issue, we credit you by name or handle — only with your consent.

Coordinated disclosure

We ask you not to publish details of the vulnerability for 120 days from our acknowledgement, so that a fix can be developed, tested and rolled out to vessels before details are public. Our products are installed on ships with long update cycles; if we need more time than that, we will tell you why and agree a new date with you. If we conclude the report is not a vulnerability or decide not to fix it, we will tell you, and you are free to publish after the 120 days.

Rules for good-faith research

We consider security research to be made in good faith when you:

  • Access, modify or delete only the data needed to demonstrate the issue — do not copy, exfiltrate or retain data beyond the minimum proof
  • Do not violate the privacy of others
  • Do not degrade or disrupt any service or device
  • Never test equipment installed on an operational vessel or otherwise in service — testing safety-related marine equipment in operation can endanger the vessel and its crew
  • Stop testing and report immediately if you encounter personal data or a safety impact
  • Do not publicly disclose details before the coordinated-disclosure timeline above
  • Comply with applicable law

Safe harbour. For research that follows these rules, EMRI will not initiate legal action against you or refer you to law enforcement, and considers the research authorised to the extent it is within EMRI’s power to authorise. EMRI cannot authorise testing of third-party systems — ship networks, hosting providers or other vendors’ equipment — and cannot bind third parties or public authorities. Research outside these rules is not covered by this safe harbour.

Out of scope

The following are not accepted under this policy:

  • Findings that require physical access to a vessel or an installed unit
  • Social engineering of EMRI staff, crews or suppliers
  • Denial-of-service or volumetric testing
  • Automated scanner output without a demonstrated security impact
  • Issues in third-party services that EMRI does not operate

Recognition

We do not operate a bug bounty and do not pay monetary rewards. We do offer public credit in the security advisory, with your consent.

Language

You can report in English or Danish. We reply in the language of your report where we can, otherwise in English.

Confidentiality

We treat the content of your report confidentially. It is shared inside EMRI on a need-to-know basis, and outside EMRI only where needed to fix the issue (for example with the maintainer of an affected third-party component) or where the law requires it (for example vulnerability notifications under Regulation (EU) 2024/2847). We never publish your identity without your consent.

About this policy

This policy implements Regulation (EU) 2024/2847 (Cyber Resilience Act) Annex I Part II points 5 and 6. Version 1.0.

Effective date: 11 September 2026

Privacy Preferences
When you visit our website, it may store information through your browser from specific services, usually in form of cookies. Here you can change your privacy preferences. Please note that blocking some types of cookies may impact your experience on our website and the services we offer.