Security

Report a vulnerability.

If you have found a security issue in MOFF, write to security@moffbridge.com. You do not need permission first, and you do not need an existing relationship with us.

Include what you found, how to reproduce it, and the version you tested against. If you would rather encrypt the report, say so in a first mail and we will arrange a key.

What we do with it

2 business days
We confirm we received your report and tell you who is handling it.
10 business days
We come back with our assessment: whether we can reproduce it, how we rate it, and what we intend to do.
90 days
Our target for having a fix available. If it takes longer we say so and explain why, rather than going quiet.

We will credit you by name in the release notes unless you prefer otherwise. We do not run a paid bounty programme.

Scope

In scope
The MOFF software itself: the bridge service, the management dashboard, the REST pull API, the signing and chain implementation, the compliance export and the standalone verifier.
Out of scope
Third-party systems MOFF connects to, a customer's own network or controllers, and this website. Findings on moffbridge.com are still welcome, they are just not a product vulnerability.

Please do not test against a live plant. If you need an environment to work in, ask and we will arrange one.

Good faith

If you research in good faith, follow this policy, keep the finding confidential until we have had a chance to fix it, and do not access, alter or destroy data that is not yours, we will not pursue legal action against you. We ask for 90 days before public disclosure, and we will work with you if there is a reason to move faster.

Regulatory reporting

MOFF is a product with digital elements under Regulation (EU) 2024/2847, the Cyber Resilience Act. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents through the ENISA Single Reporting Platform to the coordinating national CSIRT and to ENISA.

Where a report we receive meets that threshold, we file it on the statutory timeline: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within 14 days of a corrective measure being available. We will tell you when a report you sent has triggered that process.

Denmark · CVR 44047918 · security.txt

Want to see it running against your own protocols?