...

Product Security

Eccel Technology Ltd takes the security of our products seriously. We welcome reports from security researchers, customers, integrators and other parties who discover potential security vulnerabilities in our products, firmware or software.

If you believe you have discovered a security vulnerability affecting an Eccel Technology product, please report it to us using the form below or by email at security@eccel.co.uk.

Report a Security Vulnerability

Please provide as much information as possible to help us investigate the issue.

    Report a security vulnerability

    Please use this form to report a suspected security vulnerability affecting an Eccel Technology product, firmware or software. For general technical support or product enquiries, please our normal contact channels.

    Do you have evidence or reason to believe this vulnerability is currently being actively exploited?

    Please do not submit passwords, private keys, customer data or other unnecessary sensitive information through this form. If you need to provide sensitive technical material or large files, submit this form first and we will arrange an appropriate transfer method.

    Information submitted through this form will be used to investigate and respond to the reported security issue. Please see our Privacy Policy for information about how we process personal data.

    Please note: Do not include passwords, private cryptographic keys, personal data, customer data or other unnecessary sensitive information in your initial report.

    If additional files, logs, proof-of-concept code or other sensitive technical information are required, we will arrange an appropriate method for providing them after reviewing your initial report.

    What to Include in Your Report

    Where possible, please provide:

    • the affected Eccel Technology product or products;
    • hardware revision and firmware/software version;
    • the interface or protocol involved, if relevant;
    • a clear description of the vulnerability;
    • steps required to reproduce the issue;
    • the potential security impact;
    • information about any known exploitation of the vulnerability; and
    • your contact details so that we can communicate with you during our investigation.

    Providing complete information will help us assess and address the issue more efficiently.

    Scope

    This vulnerability disclosure process covers:

    • Eccel Technology hardware products with digital elements, including RFID and NFC readers and modules;
    • firmware developed and distributed by Eccel Technology for these products;
    • software and tools developed and distributed by Eccel Technology for use with these products; and
    • security issues in third-party components where the vulnerability affects an Eccel Technology product.

    Third-party applications, customer systems and integrations built using Eccel Technology products are generally outside the scope of this policy unless the reported vulnerability originates from, or is caused by, an Eccel Technology product, firmware or software component.

    Coordinated Vulnerability Disclosure

    We ask security researchers to follow responsible and coordinated vulnerability disclosure practices.

    Please:

    • report the vulnerability to us before publicly disclosing detailed information;
    • allow us reasonable time to investigate and, where necessary, develop and distribute a fix or mitigation;
    • avoid accessing, modifying, deleting or retaining data that does not belong to you;
    • avoid disrupting Eccel Technology services or systems or those of our customers;
    • avoid social engineering, phishing or physical attacks against Eccel Technology employees, offices or infrastructure; and
    • limit testing to what is reasonably necessary to demonstrate the vulnerability.

    We will investigate reports made in good faith and will work with reporters where appropriate to understand, reproduce and address valid security vulnerabilities.

    What You Can Expect From Us

    After receiving a vulnerability report, Eccel Technology will:

    • acknowledge receipt of the report;
    • perform an initial technical assessment;
    • determine the affected products and firmware/software versions;
    • assess the security impact and severity;
    • investigate appropriate corrective or mitigating measures; and
    • communicate relevant information to the reporter where appropriate.

    Where a vulnerability affects products supplied to customers, we will take appropriate steps to provide affected users with relevant security information, mitigations or updates where required.

    Certain cybersecurity vulnerabilities and incidents may also be subject to regulatory reporting requirements, including those established by the EU Cyber Resilience Act.

    Security Updates and Advisories

    Where appropriate, Eccel Technology may publish security advisories concerning vulnerabilities affecting our products.

    An advisory may include:

    • affected products and versions;
    • a description of the vulnerability;
    • an assessment of its security impact;
    • available mitigations;
    • corrected firmware or software versions; and
    • instructions for customers.

    Customers should follow the security and firmware update recommendations provided for their Eccel Technology products.

    Contact

    Security vulnerabilities should be reported to:

    Eccel Technology Ltd
    16B Fir Tree Lane
    Groby
    Leicester LE6 0FH
    United Kingdom

    Email: security@eccel.co.uk

    Alternatively, please use the security vulnerability reporting form above.

    For general technical support, sales enquiries or non-security-related questions, please use our normal contact channels instead.

    Policy Updates

    We may update this security policy and vulnerability disclosure process from time to time.

    The current version will always be available on this page.

    Last updated: 11 September 2026