The Duravant family of operating companies serve the food processing, packaging and material handling segments.
POL-CYB-01 Coordinated Vulnerability Disclosure Policy
1. Purpose
Key Technology designs and manufactures industrial food processing equipment, including optical sorting, inspection, conveying, and automation systems. Many of these products incorporate hardware, software, embedded devices, communication interfaces, and other digital technologies that may qualify as products with digital elements within the meaning of Regulation (EU) 2024/2847 (Cyber Resilience Act). Where applicable, such products have been assessed for compliance with the relevant requirements of the Regulation.
This policy explains how to report a security vulnerability identified by customers, integrators, partners, independent security researchers, or anyone else and how security vulnerability is handled.
2. Scope
This policy applies to vulnerabilities that may affect the cybersecurity of products from Key Technology with digital elements, including software developed by Key Technology and digital or software components integrated into products from Key Technology where such components may affect the cybersecurity of the product.
This policy does not apply to:
- General technical support requests
- Product complaints unrelated to cybersecurity
- Commercial enquiries
Reports concerning cybersecurity incidents may also be received through the same contact channel and will be handled through the appropriate internal processes.
3. How to Report
Security vulnerabilities may be reported through:
Ticketing System: https://service.key.net/
The vulnerability reporting channel is monitored by trained personnel responsible for coordinating vulnerability handling activities. Vulnerability reports are reviewed by designated staff and are not processed solely through automated systems.
4. What to Report
To assist in investigation, reporters should provide:
- The product name and the machine identification number
- The software version
- A clear description of vulnerability and the (potential) impact
- The steps to reproduce it, including any proof-of-concept code, scripts or screenshots
- Supporting evidence or screenshots
Incomplete reports will still be reviewed when sufficient information is available.
Vulnerabilities may also be reported through competent CSIRT channels where such channels are available under applicable EU or national coordinated vulnerability disclosure frameworks.
5. Our Response Commitments
Upon receiving a vulnerability report Key Technology will:
Acknowledgement
- Confirm receipt within 5 business days
Triage
- Assess validity and severity
- Determine affected products and versions
- Assess potential customer impact
Ongoing Communication
- Provide status updates when significant progress is made
- Coordinate remediation activities as appropriate
6. Vulnerability Handling Process
All vulnerability reports follow a documented process:
- Receipt and logging
- Initial review
- Validation and reproducibility assessment
- Severity classification
- Remediation planning
- Development and testing of corrective actions
- Release of security updates
- Customer notification
- Public disclosure where appropriate
The same process applies to vulnerabilities identified through internal testing, customers, suppliers, or external researchers.
7. Coordinated Disclosure
Key Technology supports responsible and coordinated disclosure.
We request that reporters:
- Avoid public disclosure before remediation is available
- Allow reasonable time for investigation and remediation
- Coordinate publication timing with our security team
Where possible, disclosure timelines will be agreed jointly between the reporter and Key Technology.
8. Security Advisories and Public Disclosure
When a vulnerability has been remediated, Key Technology may publish:
- Security advisories
- Release notes
- Customer notifications
- Product security bulletins
Published information may include:
- Vulnerability description
- Affected products
- Severity assessment
- Mitigation guidance
- Availability of fixes
Disclosure may be delayed if immediate publication would create unacceptable risk before customers can reasonably deploy corrective measures.
9. Confidentiality
Vulnerability reports are handled confidentially.
Information provided by reporters will only be shared with personnel involved in:
- Investigation
- Remediation
- Regulatory reporting
- Customer communications
Personal data will be processed according to applicable privacy laws and company privacy policies.
10. Policy Maintenance
This policy is reviewed periodically to ensure alignment with:
- The EU Cyber Resilience Act (CRA)
- Internal vulnerability handling procedures
- Product Security Incident Response Team (PSIRT) processes
- Evolving industry best practices
v1.0











