Matthews Marking Systems designs the equipment manufacturers rely on to mark, code, and trace their products — including the MPERIA controller platform. We understand the critical impact that cybersecurity has on industrial control systems, and we’re committed to safeguarding our products against vulnerabilities that could compromise their integrity, safety, or the operations of the customers who depend on them.

We value working together with security researchers, integrators, and customers to identify and evaluate potential vulnerabilities in our products, and to resolve them responsibly before they put that trust at risk. However, Matthews Marking Systems does not operate a bug bounty program and does not pay for vulnerability reports.

In short: If you think you have found a security problem in one of our products, tell us. Use the form below or email [email protected]. We will confirm we received your report. We will investigate it. If we confirm a problem, we will fix it and, where appropriate, publish an advisory. There is no reward or payment for reports.

Scope

The scope of this coordinated vulnerability disclosure process covers Matthews Marking Systems products, including the MPERIA controller platform and its associated software and firmware.

It is not intended for general technical support, warranty claims, or product quality issues. For those matters, please visit our Support page.

We handle vulnerabilities in products that are within their declared support period. If a product has reached end of support, we may not issue a fix. Contact Customer Support for the declared support periods for products

How to Submit

If you think you found a potential vulnerability in a Matthews Marking Systems product, please submit it through our reporting portal:

Vulnerability Submission Form

Every submission receives a tracking record, in the same spirit as the traceability our products build for our customers:

Example (Vulnerability Disclosure RecordMMS – VDR – 000482)

 

For encrypted submissions, you may also email [email protected]. Our PGP key and additional contact details are published in our security.txt file.

To assist us in our review, please include with your report any relevant artifacts or evidence that helps corroborate the existence of a potential vulnerability. Reports should include sufficient information for Matthews Marking Systems to reproduce and validate the issue. Matthews Marking Systems may decline to investigate reports that lack adequate technical detail or reproducible evidence.

Please do not send us customer data, production data, or personal data unless Matthews Marking Systems expressly requests it from you. If you believe such data is necessary to explain the issue, contact [email protected] before sending it.

You may submit your report in English, German, French, Italian, Spanish, or Swedish. If you write in another language, we will use translation tools, which may slow our response.

Upon Submission

Upon submission of a vulnerability report, Matthews Marking Systems will:

  1. Acknowledge receipt of the submission. If do not receive confirmation from us within ten (10) business days, please email us at [email protected]. Unless you provide your contact information with your submission we will not be able to contact you about your report and may be unable to address it.
  2. Verify and attempt to reproduce the reported issue independently of the product development team, potentially reaching out to you for additional detail during this phase.
  3. Assess the vulnerability’s potential impact if we confirm the existence of a vulnerability and determine appropriate remedial action and prioritize the response.
  4. Resolve the issue through a fix or mitigation appropriate to the vulnerability and the product’s lifecycle status, and coordinate a disclosure timeline with you.
  5. If disclosure is warranted, publish a notification on this page and report it to relevant external parties in accordance with our regulatory obligations. Where reasonably possible we will seek to coordinate our disclosure timeline with you.

The steps above describe our general practice. They are not commitments or guarantees, and they are subject to the Disclaimer at the end of this page.

We ask that you give us a reasonable opportunity to investigate and remediate before you share details of the issue publicly, and that you work with us on a coordinated disclosure timeline. This is a request. Nothing on this page prevents you from disclosing a vulnerability you have found in our products.

Testing Guidelines

When looking for vulnerabilities, please:

  • Test only on equipment you own or are authorized to test.
  • Do not test on customer systems or live production environments.
  • Do not access, copy, modify, or delete data that does not belong to you.
  • Stop testing immediately if you gain access to any data you are not authorized to access, and tell us right away.
  • Do not perform denial-of-service testing, physical attacks, or social engineering.
  • Do not install malware, backdoors, or persistent access of any kind.
  • Do not disrupt or degrade any system or service.

Matthews Marking Systems reserves the right not to respond to any reports that it believes come from testing outside these guidelines.

Notice

By submitting your findings through this process, you agree that your submission will be governed by our Privacy Policy and Terms of Use, and you confirm that:

  • You made a good faith effort to comply with the “Testing Guidelines” set forth above.
  • You have the right to share everything in your submission with Matthews Marking Systems.
  • You did not obtain the information unlawfully or in breach of any agreement.
  • Your submission does not include confidential information belonging to any third party.
  • Your submission does not include personal data about any other person, except where strictly necessary to describe the issue.
  • Your submission does not include export-controlled, classified, or government-controlled technical data.

As part of the submission process, we collect your email address and any other information you choose to provide so that we can acknowledge receipt of your report, communicate with you regarding our investigation, and coordinate remediation activities as needed. Your submission will be treated as non-proprietary and non-confidential, and Matthews Marking Systems will be permitted to use the information as described below. Submitting a report does not create any rights on your behalf or impose any obligations on Matthews Marking Systems beyond those described here.

Your report may involve software or components supplied by third parties. You agree that we may share your report, including your contact details where relevant, with affected suppliers, open-source maintainers, CVE Numbering Authorities, CSIRTs, ENISA, and other authorities, where we consider it necessary or where we are legally required to do so.

If you make a good-faith effort to follow this process and the Testing Guidelines above, Matthews Marking Systems will not initiate legal action against you in connection with your research or your report. This statement applies only to claims that Matthews Marking Systems itself is able to bring. It does not bind our customers, our suppliers, or any other third party, and it does not limit the actions of law enforcement or any government authority. We reserve all rights with respect to activity that does not follow this process.

We do not accept reports that are conditioned on payment, or that are accompanied by a demand, threat, or deadline for public disclosure. Submissions of that kind are not made in good faith, are not covered by the protections in this process, and may be referred to law enforcement.

Matthews Marking Systems may implement technical controls designed to detect and prevent automated, abusive, excessive, or malicious submissions.

As required under the EU Cyber Resilience Act, Matthews Marking Systems may be required to report actively exploited vulnerabilities or severe incidents to relevant regulatory authorities on a defined timeline — independent of, and in addition to, our communication with the original reporter. Matthews Marking Systems reserves the right to modify, suspend, or discontinue this vulnerability reporting process at any time and without notice.

Security Advisories

As they become available, you will find advisory information here regarding security events and their potential impact on Matthews Marking Systems products.

Summary Link
No current alerts  
   

Disclaimer

Any suggestions, feedback, recommendations, ideas, discoveries, observations, or other information submitted to Matthews Marking Systems in connection with a vulnerability report may be used by Matthews Marking Systems for any purpose without restriction and without compensation to you. Matthews Marking Systems shall own all right, title, and interest in any fixes, corrections, updates, enhancements, security advisories, or other materials developed by Matthews Marking Systems based on or in response to such submissions. To the extent you hold any intellectual property rights in your submission, you grant Matthews Marking Systems a perpetual, irrevocable, worldwide, royalty-free, transferable, and sublicensable license to use, reproduce, modify, distribute, disclose, and create derivative works from your submission for any purpose, and you waive any moral rights in the submission to the maximum extent permitted by applicable law.

Submission of a vulnerability report does not entitle you to any compensation, bounty, reward, reimbursement, public acknowledgement, attribution, license, ownership interest, or other benefit unless Matthews Marking Systems expressly agrees otherwise in a separate writing signed by an authorized representative of Matthews Marking Systems.

The vulnerability reporting process described on this page is provided solely to facilitate the submission of potential security vulnerabilities relating to products and services offered by Matthews Marking Systems. Matthews Marking Systems reserves the right, in its sole discretion, to reject, disregard, or close any report that Matthews Marking Systems determines to be incomplete, duplicative, unverifiable, automated, abusive, misleading, non-security related, generated principally through automated means without sufficient supporting evidence, or otherwise unsuitable for investigation.

Nothing contained on this page, and no action or inaction by Matthews Marking Systems in connection with any vulnerability report, shall be construed as:

  • Creating any express or implied warranty;
  • Modifying, expanding, extending, or otherwise affecting any warranty applicable to any Matthews Marking Systems product or service;
  • Creating any service-level commitment, support obligation, remediation obligation, or response-time commitment;
  • Constituting a representation that any reported issue is valid, reproducible, security-related, or will be remediated within any particular timeframe; or
  • Creating any contractual relationship between Matthews Marking Systems and the reporting party.

All warranties applicable to Matthews Marking Systems products and services are governed exclusively by the applicable purchase agreement, master agreement, license agreement, terms of sale, or other written agreement between Matthews Marking Systems and the end customer.

To the maximum extent permitted by applicable law, Matthews Marking Systems disclaims all liability arising out of or relating to:

  • The submission of any vulnerability report;
  • Matthews Marking Systems’ review, investigation, prioritization, validation, rejection, remediation, disclosure, or non-disclosure of any reported issue;
  • Any delay in responding to, investigating, or remediating a reported issue;
  • Any decision regarding whether, when, or how a vulnerability is disclosed or addressed; and
  • Any reliance by a reporting party or third party on information provided by Matthews Marking Systems through this reporting process.

Matthews Marking Systems makes no representation or warranty regarding the accuracy, completeness, availability, or timeliness of any communication related to a vulnerability report.

Nothing in this disclaimer is intended to exclude or limit liability to the extent such exclusion or limitation is prohibited by applicable law. If there is any conflict between this Disclaimer and any other statement on this page, this Disclaimer controls.

Talk to a Solutions Engineer

Contact us to get a quote, request samples, schedule a demonstration, or receive additional product information.