What can you report?
Report potential vulnerabilities in ServiceGate routers, controllers, firmware, the Remote Portal, our app and software and services developed by us. For custom solutions, identify the application and implementation.
This policy does not authorise testing customer environments or third-party systems. Conduct active research only in your own isolated test environment or under separately agreed permission. You can report a suspicion without additional testing.
How to submit a useful report
Email security@remoteengineer.eu and include, where possible:
- Product, model, hardware revision and firmware or software version.
- The affected service or URL.
- Your finding and its potential impact.
- The minimum steps needed to reproduce the issue safely.
- Limited technical evidence and a way to contact you.
Do not send passwords, private keys, complete customer files or unnecessary personal data. Before sending sensitive details, ask for a suitable transfer method and wait until it has been agreed. We also accept anonymous reports; without contact details, we cannot ask follow-up questions or provide feedback.
Research without causing harm
- Limit research to what is necessary to demonstrate the vulnerability.
- Do not modify or delete data, install a backdoor or retain unnecessary access.
- Stop if you unintentionally access other people’s data; do not copy or distribute it.
- Do not use phishing, social engineering, brute force or disruptive attacks.
- Do not use our products or services to access downstream customer networks.
- Do not test operational installations without separate permission and safety arrangements.
Physical safety comes first. Research must not affect machine movements, pump operation or other physical processes. On vessels, it must not involve controlling course or speed.
How we handle your report
We acknowledge receipt within three working days. We assess technical impact and urgency as soon as possible. In our first substantive response, we agree when you will receive the next update. Remediation timing depends on risk, impact and technical dependencies; we do not guarantee a fixed resolution time for every issue.
We treat reports and contact details confidentially. Where cooperation with an affected supplier, coordinator or competent authority is necessary, we limit sharing to relevant information and take legal obligations into account.
Urgent reports do not wait for the acknowledgement deadline. Indications of active exploitation are escalated internally immediately. Statutory reporting deadlines are assessed separately and take precedence over our feedback schedule.
We coordinate disclosure together
Give us a reasonable opportunity to investigate and protect users before publishing technical details. Together we discuss an appropriate timeline, considering severity, potential exploitation and available measures. We explain any postponement; confidentiality is not indefinite.
With your permission, we may acknowledge you as the discoverer. Reporting a vulnerability does not guarantee financial compensation.
Legal commitment
If you act in good faith and remain within this policy, we will not take legal action against you for that research or report. This commitment is made solely on behalf of Remote Engineer. We cannot make commitments on behalf of customers, other parties or competent authorities.
Resolving issues responsibly
Unsure whether your finding falls within this policy? Send a brief description to security@remoteengineer.eu, without sensitive data. Do not carry out additional tests solely to establish the scope.
This policy is not evidence of CRA conformity and does not replace statutory reporting procedures.

