at grapho metronic
Discovered a vulnerability?
The security of our products is of very high importance to grapho metronic.
If you have discovered a potential vulnerability, we encourage you to report it to us responsibly and privately.
What should your report include?
To enable us to review and process your report as quickly as possible, please include the following information:
Our Vulnerability Disclosure Policy
grapho metronic values the security of our products. We encourage security researchers, customers, and any other third parties to report vulnerabilities responsibly so we can investigate and remediate them in a coordinated manner.
Our Vulnerability Disclosure Policy explains how to report vulnerabilities to us, what to expect after reporting, and what testing activities are permitted.
What happens after you submit a report?
01 – Acknowledgement of receipt
Within 1 business day
02 – Initial assessment
Within 3 business days
03 – Status update
As needed, especially if remediation takes longer
04 – Coordinated disclosure
Agreement on further measures
We handle reports in accordance with our Vulnerability Disclosure Policy. We will not initiate legal action against individuals who act in good faith, with reasonable care, and in compliance with this policy.
We do not operate a bug bounty programme and do not offer monetary compensation for vulnerability reports.

