Impressum / Imprint
Phenospex B.V.
Jan Campertstraat 11
6416 SG Heerlen
The Netherlands
Tel.: +31 (0)457 111 693
Email: info@phenospex.com
Website: www.phenospex.com
Management Board:
Dr. Grégoire Hummel, Stefan Schwartz, Dr. Christoph Bremus
Chamber of Commerce Registration:
KvK: 54212677
VAT Identification Number:
NL 851216456B01
Content Responsibility in Accordance with § 10 Absatz 3 MDStV:
Dr. Grégoire Hummel
Phenospex B.V.
Jan Campertstraat 11
6416 SG Heerlen
The Netherlands
Security & Vulnerability Reporting
At Phenospex, we take the security of our software and systems seriously. If you believe you have discovered a security vulnerability in our products or infrastructure, we encourage you to report it to us immediately so we can take appropriate action.
Regulatory Compliance (EU Cyber Resilience Act – Regulation (EU) 2024/2847)
Our vulnerability handling and reporting processes comply with the EU Cyber Resilience Act (CRA). In accordance with Annex I, Part II (Vulnerability Handling Requirements) and Article 13 (Coordinated Vulnerability Disclosure), we maintain a public channel for reporting security issues. In line with Article 14 of the CRA, reported submissions are timestamped upon receipt, assessed against regulatory criteria, and formally reported to European authorities (including ENISA) within the 24-hour and 72-hour statutory windows if an actively exploited vulnerability or severe incident is identified.
How to Report a Vulnerability: Please submit all security-related reports via email to: security@phenospex.com
To help us triage and resolve the issue as quickly as possible, please include the following information in your email:
- The affected product, software version, or specific service.
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce the issue (including any proof-of-concept code, screenshots, or logs).
Responsible Disclosure Guidelines We ask that you follow standard responsible disclosure practices:
- Do not take advantage of the vulnerability to access, modify, delete, or expose user data.
- Do not perform attacks that could degrade or disrupt our services (e.g., DoS/DDoS).
- Please keep the vulnerability confidential and do not share it publicly or with third parties until we have had the opportunity to investigate and deploy a fix.
What to Expect Our security team reviews all submissions. Upon receiving your report, we will log the exact time of receipt for our regulatory compliance processes. We will evaluate the submission, determine the severity, and inform you if we need to deploy any necessary updates.








