If you have found a security issue in MOFF, write to security@moffbridge.com. You do not need permission first, and you do not need an existing relationship with us.
Include what you found, how to reproduce it, and the version you tested against. If you would rather encrypt the report, say so in a first mail and we will arrange a key.
We will credit you by name in the release notes unless you prefer otherwise. We do not run a paid bounty programme.
Please do not test against a live plant. If you need an environment to work in, ask and we will arrange one.
If you research in good faith, follow this policy, keep the finding confidential until we have had a chance to fix it, and do not access, alter or destroy data that is not yours, we will not pursue legal action against you. We ask for 90 days before public disclosure, and we will work with you if there is a reason to move faster.
MOFF is a product with digital elements under Regulation (EU) 2024/2847, the Cyber Resilience Act. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents through the ENISA Single Reporting Platform to the coordinating national CSIRT and to ENISA.
Where a report we receive meets that threshold, we file it on the statutory timeline: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within 14 days of a corrective measure being available. We will tell you when a report you sent has triggered that process.
Denmark · CVR 44047918 · security.txt
Want to see it running against your own protocols?