Security

Security at E-Sharp

E-Sharp AB builds test and traceability systems that our customers rely on in production. We take reports of security vulnerabilities in our products seriously, and we would rather hear about a problem from you than from an incident.

If you have found a security issue in an E-Sharp product, please tell us.

How to report

This address is monitored and goes directly to a member of E-Sharp’s management. Please do not report security issues through public channels — GitHub issues, support tickets, social media, or our general contact form.

If you need to send us something encrypted, email us first and we will arrange a secure channel.

What to include

The more of this you can give us, the faster we can act. Send what you have; a partial report is far better than no report.

  • The product and version affected.
  • What the issue is, and what an attacker could do with it.
  • Steps to reproduce it — a proof of concept, script, or screen recording if you have one.
  • Anything about your environment that mattered: configuration, network position, other software involved.
  • How you would like to be credited, if you would like to be credited at all.

Our commitments to you

We willWithin
Acknowledge your report and confirm a human is reading it24 hours
Give you our initial assessment — whether we can reproduce it, and how serious we think it is5 working days
Keep you updated while we work on itAt least every 14 days
Tell you when it is fixed, and what we shippedOn release

We will tell you honestly if we decide not to fix something, and why. We will not quietly let a report go cold.

We do not currently run a paid bug-bounty programme. We do offer public credit to anyone who wants it, and we are glad to confirm your findings in writing for your own records or disclosure.

Safe harbour

If you make a good-faith effort to follow this policy, E-Sharp will not pursue or support legal action against you for your research, and we will treat your work as authorised.

We consider research conducted under this policy to be authorised, and we will say so if a third party questions it. If a court or authority nonetheless comes after you for research you carried out in good faith under this policy, tell us — we will make our position clear.

If you are unsure whether something is in scope or whether a particular test is acceptable, ask us first at security@esharp.se. Asking never counts against you.

What we ask of you

To stay within this policy, please:

  • Do not access, modify, or delete data that is not yours. If you demonstrate access to data, stop at the minimum needed to prove the point.
  • Do not degrade our services or our customers’. No denial-of-service testing, no load or stress testing, no automated scanning that generates significant traffic.
  • Do not use social engineering, phishing, or physical intrusion against E-Sharp staff, customers, or premises.
  • Tell us immediately if you encounter personal data, credentials, or customer information, and do not retain a copy.
  • Give us reasonable time to fix the issue before disclosing it publicly — see below.

Coordinated disclosure

We ask that you give us 90 days from your initial report before disclosing publicly. Most issues are resolved well inside that.

If we need longer — some fixes have to reach hardware in the field, which is genuinely slow — we will explain why and agree a date with you rather than simply asking for more time. If we cannot fix something, we will say so and agree with you how it should be disclosed.

We are happy to coordinate a joint advisory, and to publish on the same day you do.

Scope

In scope — E-Sharp products and services:

  • Maestro — test execution software, station and central components
  • Trace — engineering traceability platform, including its web interface
  • Probe — design review and analysis platform
  • E-Sharp MCP servers for the products above
  • Sparrow test systems and modules
  • Accordion A2 instruments and sub-assemblies
  • E-Sharp USB PD power supplies
  • E-Sharp websites: esharp.se, demo.esharp.se, help.esharp.se

Out of scope

  • Third-party services we use but do not operate, such as our hosting provider, email provider, or code-hosting platform. Report those to their owners.
  • Customer-operated deployments of our products where the finding is in the customer’s own configuration or infrastructure rather than in our product. Tell us anyway — we will help you reach the right people.
  • Systems and networks belonging to E-Sharp customers.

Unlikely to act on

Unless you can show real-world impact:

  • Missing security headers, or TLS configuration findings, on our marketing site with no demonstrated exploit.
  • Self-XSS, or issues that require an already-compromised device or browser.
  • Missing rate limiting without a demonstrated attack.
  • Output from an automated scanner with no proof of concept.
  • Reports about software versions being outdated, absent a specific exploitable vulnerability.

Send it regardless if you think it matters. This list exists to set expectations, not to shut down the conversation.

Regulatory reporting

E-Sharp AB is a manufacturer of products with digital elements under the EU Cyber Resilience Act (Regulation (EU) 2024/2847).

Where a vulnerability in one of our products is being actively exploited, or where a severe incident affects the security of one of our products, we report it to CERT-SE and ENISA on the timelines set out in Article 14 of that Regulation, and we inform affected users directly.

Reporting a vulnerability to us under this policy does not put you under any obligation of your own.

Contact

security@esharp.se — vulnerability reports and security questions
www.esharp.se — everything else

E-Sharp AB, Sweden

Last updated: 2026-08-24