Product Security and Vulnerability Reporting
Daikin Applied Europe S.p.A. considers the security of products and services with digital elements to be an essential component of their quality throughout their lifecycle. For this reason, we provide a dedicated reporting channel for researchers, customers, partners, and other individuals who wish to responsibly disclose a potential vulnerability.
Vulnerability disclosures are voluntary. Daikin Applied Europe S.p.A. does not operate a bug bounty program and does not provide compensation, rewards, or any other form of financial remuneration for reported vulnerabilities.
How we handle a report
Responsible Research and Coordinated Disclosure
We welcome reports submitted responsibly and in good faith. We ask anyone who identifies a potential vulnerability to:
- act with due care, avoiding any harm or negative impact on the security, safety, health, or privacy of individuals, as well as on assets, data, systems, or services;
- conduct testing only on products or systems they lawfully own, control, or are authorized to test, or after obtaining prior authorization from the relevant owner;
- comply with applicable laws and respect the rights of third parties;
- limit activities to what is strictly necessary to verify the existence and impact of the potential vulnerability;
- avoid modifying or deleting data, altering systems, disrupting or degrading services, or accessing data beyond what is necessary to verify the vulnerability;
- refrain from using social engineering, phishing, physical attacks, denial-of-service attacks, large-scale brute-force techniques, malware deployment, or any other destructive or potentially harmful methods;
- not exploit the vulnerability for improper financial gain, unauthorized access to other systems, or any purpose other than verification and responsible reporting;
- submit the report to Daikin Applied Europe S.p.A. without undue delay, using the indicated reporting channels and providing sufficient information to enable us to understand, reproduce, and assess the issue;
- follow the principle of coordinated disclosure by refraining from publicly disclosing vulnerability details before the deadline agreed upon with Daikin Applied Europe S.p.A.;
- cooperate in good faith during the analysis, verification, and remediation of the vulnerability.
1. Report
Daikin Applied Europe S.p.A. has established a single point of contact for reporting a potential vulnerability affecting a product or service with digital elements. This point of contact can be reached through one of the following methods:
- by sending an email to productsecurity@daikinapplied.eu. To protect sensitive technical information, we recommend encrypting the message and any attachments using our PGP public key. Please do not include sensitive technical details in the subject line of the message.
Pubblic PGP Key
- by completing the online form, which forwards the information to the same email address indicated above and is processed through the same vulnerability management workflow.
The Product Security team will provide an initial response within one business day of receiving the report. This initial response confirms receipt of the report and, where possible, indicates whether additional information is required. It does not constitute confirmation of the existence of a vulnerability, its severity, or the time required to address it. To facilitate assessment, please include, where available:
- a description of the issue and its potential impact;
- the product name, model, variant, serial number, and affected software, firmware, or hardware version;
- steps to reproduce the behavior, proof of concept, relevant logs, or network traces;
- the conditions required for exploitation and any necessary privileges;
- any temporary workarounds or mitigations already identified;
- details of any prior publication or sharing of the information;
- the date the vulnerability was identified and, if known, whether it is being actively exploited;
- whether you are willing to assist in verifying a fix or mitigation.
Please do not include personal data, credentials, third-party information, or any other content not necessary for verification. For particularly sensitive documentation, please use PGP-encrypted email. The Product Security reporting channel is reserved exclusively for reports concerning the security of products and services with digital elements. For routine technical support, spare parts requests, commercial inquiries, complaints, or whistleblowing reports, please use the respective dedicated channels.
2. Technical Assessment
Il team competente effettua un primo triage, verifica che la segnalazione rientri nell’ambito della Product Security e, quando possibile, prova a riprodurre il problema. Potremmo contattare il segnalante per richiedere chiarimenti o ulteriori evidenze tecniche.
3. Management
When a vulnerability is confirmed, the functions responsible for the product are engaged to assess the associated risk and determine the most appropriate actions, including potential fixes, updates, mitigations, or other risk-reduction measures. Where useful and practicable, the reporter may be involved in verifying the effectiveness of the implemented measures.
4. Disclosure
When it is necessary to inform users, Daikin Applied Europe S.p.A. provides guidance through the appropriate communication channels. When a security update addressing a remediated vulnerability is made available, Daikin Applied Europe S.p.A. shares and publicly discloses the relevant information, including through a Security Advisory. Communication is coordinated to reduce exposure to risk. In cases where the security risks associated with disclosure outweigh its benefits, disclosure may be delayed to allow users sufficient time to implement the available mitigations or corrective measures.
Security Advisory
Security Advisories inform customers and users about vulnerabilities affecting identified products or product versions and provide the information necessary to assess exposure and apply updates, corrective actions, or mitigations.
Last Update: September 2026

