Security

This page sets out how to report a vulnerability to AviaVox, where the AviaVox coordinated vulnerability disclosure policy is published, and where AviaVox publishes information concerning vulnerabilities that have been resolved.

AviaVox supplies voice announcement systems that operate in live transportation environments. A vulnerability in an AviaVox product may affect the integrity or availability of announcements made to passengers. AviaVox therefore treats such vulnerabilities as a matter of operational safety as well as of information security.

Restrictions on testing

Production AviaVox installations must not be tested, scanned, or subjected to any attempt at exploitation.

Production installations are operational transportation systems. Testing against such a system may affect announcements made to passengers, with consequences for the safety of our customer’s operations. Unauthorised access to a customer’s operational system may also constitute a criminal offence under Dutch law.

Where an environment is required in order to validate a finding, contact security@aviavox.com. AviaVox will determine what can be made available.

The safe harbour undertaking given in the disclosure policy is subject to two limits. It is given by AviaVox on its own behalf and does not extend to AviaVox customers or to the operators responsible for the systems concerned. It does not displace applicable law. Testing a customer installation falls outside its scope.

Reporting a vulnerability

Email: security@aviavox.com
Monitored: Monday to Friday, 09:00–17:00 CET/CEST, excluding Dutch public holidays

security@aviavox.com is the single point of contact for the reporting of vulnerabilities in AviaVox products, as required by Article 13(17) of Regulation (EU) 2024/2847.

Where a reporter has grounds to believe that a vulnerability is being actively exploited, the subject line of the report should begin with ACTIVE EXPLOITATION. Reports marked in this way are examined ahead of the standard queue.

Reports received through other AviaVox channels, including technical assistance, an account manager, a reseller, or an established contractual contact, are handled under the same policy and against the same commitments. AviaVox personnel are instructed to forward such reports to security@aviavox.com without delay. A second report is not required, although correspondence addressed directly to security@aviavox.com reaches the responsible team most quickly.

A report should state the product and version affected, the configuration tested, the steps taken, the result observed, and the reporter’s assessment of the impact. Reporters are asked not to include more customer data or personal data than is necessary to demonstrate the finding.

Anonymous reports are accepted. Where a report is submitted anonymously, AviaVox is unable to request clarification or to communicate the outcome to the reporter.

AviaVox does not operate a bug bounty programme and does not offer payment for reports. AviaVox does not maintain a public acknowledgements page and does not name reporters in advisories.

Coordinated vulnerability disclosure policy

The AviaVox coordinated vulnerability disclosure policy is published at https://aviavox.com/wp-content/uploads/2026/09/CRA-AL-01-Coordinated-Vulnerability-Disclosure-Policy-AviaVox.pdf. It defines the products and components within scope, the handling of a report following receipt, the commitments AviaVox gives in response, the treatment of personal data, and the protections available to reporters acting in good faith.

Response commitments and assessment periods are stated in the policy and are not reproduced on this page. The version published at that address is the operative version. Material changes are recorded in the policy’s document control table.

Security advisories

AviaVox publishes information concerning resolved vulnerabilities on this page.

As at 11 September 2026, no advisories have been published.

An advisory is published once a vulnerability affecting a supported AviaVox product has been resolved and a security update is available. Each advisory states the nature of the vulnerability, the products and versions affected, the assessed impact and severity, and the action required of customers. Where earlier publication would increase the risk to users, in particular before a remedy is available, the timing of publication is coordinated with the relevant national CSIRT.

Security updates are supplied free of charge to customers holding a supported installation, and are issued separately from feature releases.

Affected customers are notified directly through their established AviaVox contact. Customers requiring additional recipients to be included in security notifications should notify security@aviavox.com.

Third-party and open-source components

AviaVox products incorporate third-party and open-source components. A vulnerability in such a component, to the extent that it affects an AviaVox product, is within scope for reporting.

Where a report concerns a third-party or open-source component, AviaVox reports the matter to the entity maintaining that component. The timing of any disclosure is coordinated with the reporter in advance.

Customers requiring information on the components incorporated in a delivered system, for the purposes of their own risk assessment, may request it through their AviaVox contact.

Notification of severe incidents

Where an actively exploited vulnerability or a severe security incident affects an AviaVox product, AviaVox informs the affected customers without undue delay and states the corrective measures required of them. Information may also be published on this page.

Regulatory framework

AviaVox is a manufacturer within the meaning of Regulation (EU) 2024/2847, the Cyber Resilience Act. With effect from 11 September 2026, AviaVox notifies actively exploited vulnerabilities in its products, and severe security incidents affecting them, to the designated national CSIRT in the Netherlands and to ENISA, by means of the Single Reporting Platform and within the periods prescribed by the Regulation.

A report submitted to AviaVox may be disclosed to those authorities. The identity of the reporter is not disclosed to them, except with the reporter’s consent or where disclosure is required by law. The handling of personal data contained in a report is described in the disclosure policy and in the AviaVox privacy policy at https://aviavox.com/privacy-policy/.

Revision Date: 11 September 2026