Responsible Vulnerability Management
Airedale provides responsible vulnerability management to help improve the safety and security of our products and connected solutions.
Airedale encourages a coordinated disclosure of product vulnerability management:
At Modine, the security and resilience of our products and solutions are paramount. In support of the Cyber Resilience Act, Regulation (EU) 2024/2847, we encourage our customers and security researchers in the European Union and United Kingdom to report any vulnerabilities they discover in our products. For purposes of this policy, “Modine” means Modine Manufacturing Company and its subsidiaries and affiliates when such entity makes a product available in the European Union or the United Kingdom.
This policy applies to any security vulnerabilities identified in Modine products and solutions including products with digital elements, during their active support period. This policy outlines our approach to receiving, validating, and mitigating vulnerabilities in alignment with the Cyber Resilience Act, Regulation (EU) 2024/2847.
We encourage you to read this vulnerability disclosure policy carefully before submitting a vulnerability report and to comply with its requirements at all times.
If you believe you have found a security vulnerability in a Modine product, please submit your report to us via the contact form below.
To help us triage the issue, please complete the form below to include details of:
- The affected product name, serial number, model and software version.
- A brief description of the vulnerability.
Our response team will be in touch to request further details.
Secure communication: We recommend protecting sensitive vulnerability information. Our PGP public key and security.txt is available at: Download PGP Key and Download Securtiy.txt.
Reports should be submitted only through these reporting channels. Do not communicate or share vulnerability details through any other means.
Note: Modine does not offer monetary rewards or financial compensation for vulnerability disclosures.
- Response & Triage: We will acknowledge receipt of your report within 5 working days and aim to triage your report within 10 working days.
- Priority for remediation is assessed by looking at the impact, severity and exploit complexity. Vulnerability reports might take some time to triage or address. This allows our teams to focus on the remediation.
- We will notify you when the reported vulnerability is remediated, and you may be invited to confirm that the solution covers the vulnerability adequately.
To protect our customers and ensure a safe disclosure process you must adhere to the following guidelines:
- Compliance with laws: Do not violate any applicable law or regulations or demand financial compensation in exchange for disclosing a vulnerability.
- Excessive data: Limit data access to only what is strictly necessary to demonstrate a vulnerability. Do not violate the privacy of Modine users or staff, or any other individual.
- Data modification: Refrain from modifying data in Modine’s systems or services.
- Destructive testing: Avoid using high-intensity invasive or destructive scanning tools.
- Denial of service: Do not overwhelm a service with a high volume of requests to disrupt or disable our products or services.
- Social engineering: Do not subject Modine’s employees, contractors or customers to social engineering or phishing.
- Data retention: Securely delete all data obtained during your research as soon as it is no longer required, or within one month after the vulnerability has been resolved, whichever occurs first.
This policy is intended to support responsible vulnerability disclosure and coordinated remediation of security vulnerabilities. Modine values the work of independent security researchers and is committed to collaborating to protect our users. However, nothing in this policy authorizes any activity that is unlawful, inconsistent with applicable laws or regulations, or otherwise prohibited. Individuals submitting vulnerability reports must comply with all applicable laws and must not access, modify, disclose, destroy, or retain data except to the extent strictly necessary to demonstrate a reported vulnerability and in accordance with this policy.
Modine reserves all rights and remedies available under applicable law with respect to activities that fall outside the scope of this policy. Submission of a vulnerability report does not create any contractual, employment, agency, or other legal relationship with Modine.
Modine may update this policy from time to time to reflect changes in applicable laws, regulations, industry standards, business practices, or company requirements. The most current version of this policy will be published on Modine’s websites.




