Coordinated Vulnerability Disclosure Policy
KEMARO AG Last updated: 18.08.2026
1. Our commitment
KEMARO AG takes the security of our products, including the robots and its associated software, seriously. We welcome reports from security researchers, customers, and integrators who discover potential vulnerabilities, and we are committed to working with reporters to understand and resolve issues quickly.
This policy explains how to report a vulnerability to us, what you can expect from us in response, and the ground rules we ask reporters to follow.
2. Scope
This policy applies to:
- KEMARO hardware products, including the K900 and K700 generations and their software
- Sphere, our cloud platform connected to the robots (sphere.kemaro.ch)
- kemaro.ch and any other websites or online services operated by KEMARO AG
If you are unsure whether something is in scope, report it anyway — we would rather review a report that turns out to be out of scope than miss a real issue.
3. How to report
Send a report to:
This is the only channel we currently offer, but it reaches a real person directly — we do not require automated forms or tools.
Please include, as far as you're able to:
- A description of the vulnerability and its potential impact
- The product, software version, and configuration affected
- Steps to reproduce, or proof-of-concept code/screenshots if available
- Information whether you believe the vulnerability is being actively exploited
4. Rules of engagement
When researching a potential vulnerability, please consider the following rules:
- Only test against your own equipment, test/demo environments, or with the explicit written permission of the robot's owner. Do not test against a robot deployed at a customer site without that customer's authorization.
- Avoid any action that could jeopardize the physical safety of any person. Our robots operate in active industrial environments — do not attempt to interfere with sensors, obstacle detection, emergency stops, or movement controls in a way that could put anyone at risk. This includes your own test unit, since safety-related testing can still produce unpredictable behaviour. Any activity that risks physical harm falls outside this policy and will not be covered by the commitments below.
- Do not perform denial-of-service testing, physical tampering, or social engineering against KEMARO staff, contractors, or customers.
- Avoid privacy violations, data destruction, or degrading our services or our customers' operations. Access or exfiltrate only the minimum data needed to demonstrate the issue.
- Give us a reasonable opportunity to investigate and remediate before sharing any details publicly or with third parties.
5. Our commitment (safe harbor)
If you make a good-faith effort to follow this policy, we commit to the following:
- Response: We will acknowledge receipt of your report within 3 business days, with an initial evaluation and an expected resolution timeline based on severity.
- No legal action: We will not pursue legal action against you for your report. We consider research conducted in good faith and in line with this policy to be authorized activity, including under the Swiss Criminal Code (Schweizerisches Strafgesetzbuch) provisions on unauthorized data access (e.g. Art. 143bis StGB). If your report concerns a product also placed on the EU market, we likewise do not regard good-faith, policy-compliant testing as unauthorized under applicable EU law.
- Confidentiality: We will handle your report and personal details in confidence and will not share them with third parties without your permission.
- Communication: We will keep you informed of our progress at reasonable intervals until the issue is resolved or closed.
- Credit: With your permission, we will credit you by name in any public advisory once a fix is available.
If we believe a reported vulnerability is being actively exploited, or otherwise meets the threshold of a severe incident, we may have separate regulatory reporting obligations — for example under the EU Cyber Resilience Act, which requires us to notify ENISA and the relevant national authority within 24 hours of becoming aware of active exploitation. This regulatory reporting runs in parallel with, and does not replace, our commitments to you above.
6. Coordinated disclosure timeline
We ask that you give us a reasonable opportunity to investigate and address a reported vulnerability before making any details public. As a general guideline, we aim to resolve or mitigate reported vulnerabilities within 90 days of a validated report. If a fix will take longer, or if a vulnerability is already being actively exploited (where timelines may be much shorter), we will coordinate the schedule and a disclosure date with you.
7. Out of scope
The following are generally not considered valid vulnerability reports:
- Reports generated purely by automated scanning tools without any manual validation or explanation of impact
- Findings that require physical, unsupervised access to a robot you do not own or have authorization to test
- Best-practice recommendations without a demonstrated, exploitable vulnerability
8. Recognition
We currently do not operate a paid bug bounty program, but we are glad to publicly credit researchers (with permission) for valid reports that lead to a fix.
9. Contact
- Email: security@kemaro.ch
- This policy: kemaro.ch/security-policy
- security.txt: kemaro.ch/.well-known/security.txt
This policy may be updated occasionaly. Material changes will be reflected on this page with an updated "Last updated" date.



