Coordinated Vulnerability Disclosure Policy
TP Silva Oy
1. Purpose
TP Silva Oy is committed to the security of its products and to protecting its customers and users from cybersecurity risks.
We welcome reports from customers, security researchers, partners and other parties who identify potential security vulnerabilities in our products, software or connected services.
This Coordinated Vulnerability Disclosure Policy describes how security vulnerabilities can be reported to TP Silva Oy and how we handle such reports.
2. Scope
This policy applies to products and associated digital services supplied by TP Silva Oy under the following brands:
- Japa
- Palax
- Hakki Pilke
- X Firewood Factory
The policy covers products with digital elements, including, where applicable:
- embedded control systems and software;
- operator displays and user interfaces;
- firmware;
- connectivity and IoT functionality;
- cloud-connected functions and services;
- web-based services associated with the products; and
- third-party software and hardware components integrated into TP Silva Oy products.
Vulnerabilities in third-party components used in our products may also be reported to us.
3. Reporting a Vulnerability
If you believe you have identified a security vulnerability affecting a TP Silva Oy product or associated digital service, please report it to:
security@tpsilva.fi
Please use the subject line:
Security Vulnerability Report – [Product / Brand]
To help us investigate the issue efficiently, please include as much of the following information as possible:
- affected brand and product;
- product model;
- serial number, if available and relevant;
- software or firmware version, if known;
- detailed description of the suspected vulnerability;
- steps required to reproduce the issue;
- potential security or safety impact;
- proof of concept, logs, screenshots or other supporting information, where available;
- whether you believe the vulnerability is being actively exploited; and
- your contact details for further communication.
Please do not include unnecessary personal, confidential or customer data in your report.
4. What You Can Expect from Us
When we receive a vulnerability report, TP Silva Oy will:
- aim to acknowledge receipt of the report within five working days;
- review the information and assess whether the reported issue constitutes a security vulnerability;
- request additional information where necessary;
- assess the potential cybersecurity and product safety impact;
- investigate affected products, software and components;
- coordinate with relevant component or service providers where necessary;
- develop appropriate corrective or mitigating measures based on the risk;
- keep the reporter informed of material progress where appropriate; and
- communicate relevant security information and corrective actions to affected users where appropriate.
The time required to investigate and resolve a vulnerability will depend on its complexity, severity, affected products, availability of updates and potential safety implications.
5. Coordinated Disclosure
We ask reporters to follow coordinated vulnerability disclosure principles.
Please allow TP Silva Oy reasonable time to investigate, develop, test and distribute appropriate corrective or mitigating measures before publicly disclosing technical details of a vulnerability.
We will work with the reporter, where appropriate, to coordinate the timing of disclosure.
Where a security update or other corrective measure is made available, TP Silva Oy may publish information about the vulnerability, affected products, its severity and potential impact, and recommended actions for users.
In justified circumstances, public disclosure may be delayed where immediate publication could increase cybersecurity or safety risks before affected users have had a reasonable opportunity to apply the corrective measures.
6. Responsible Security Research
TP Silva Oy supports good-faith security research carried out responsibly and in accordance with this policy.
Security research must be conducted in a way that avoids harm to people, property, systems, production processes, customers and other users.
Researchers must not:
- intentionally access, modify, copy or disclose data belonging to other users or customers;
- perform denial-of-service (DoS or DDoS) attacks;
- intentionally disrupt production systems, connected services or customer operations;
- use social engineering, phishing or similar techniques against TP Silva Oy employees, partners, dealers or customers;
- physically access premises, machines or systems without authorisation;
- install persistent access mechanisms or malware;
- intentionally damage or destroy data, equipment or software; or
- use a vulnerability beyond what is reasonably necessary to demonstrate its existence and impact.
If sensitive or personal information is unintentionally accessed during research, stop testing and report the issue to us immediately. Do not retain, copy or disclose the information.
7. Product Safety
Many TP Silva Oy products are machines containing moving components and potentially hazardous functions.
Cybersecurity testing must never compromise machine safety.
Do not perform testing that may:
- unexpectedly start or operate a machine;
- cause uncontrolled or unintended machine movement;
- disable, bypass or interfere with safety functions;
- interfere with emergency stop functions, guards, sensors or other protective systems;
- expose operators or other persons to hazardous situations; or
- cause damage to machinery, property or the environment.
Testing on operational machinery should only be performed in a controlled environment with appropriate authorisation and safety precautions.
If you identify a cybersecurity vulnerability that could have an immediate impact on machine or operator safety, please clearly mark the report as:
URGENT – SAFETY RELATED
8. Third-Party Components and Services
TP Silva Oy products may contain software, hardware, connectivity or cloud components supplied or maintained by third parties.
If a reported vulnerability affects a third-party component integrated into a TP Silva Oy product, we may coordinate the investigation and remediation with the relevant supplier or service provider.
Information necessary to investigate and resolve the vulnerability may therefore be shared with relevant parties while taking reasonable measures to protect sensitive information.
9. Security Updates and Advisories
Where appropriate, TP Silva Oy will provide security updates, mitigations, configuration changes or other corrective measures to address identified cybersecurity vulnerabilities.
Information about fixed vulnerabilities may include:
- a description of the vulnerability;
- affected products and versions;
- severity and potential impact;
- available security updates or mitigations; and
- actions recommended for users.
Customers are encouraged to apply security updates and recommended mitigations in a timely manner.
10. Good-Faith Reporting
TP Silva Oy does not intend to pursue legal action against security researchers solely for good-faith security research performed in accordance with this policy.
This does not authorise activities that are unlawful, unsafe, destructive, disruptive or outside the scope of this policy.
If you are uncertain whether a planned security test is permitted, please contact us before proceeding.
11. Bug Bounty
TP Silva Oy does not currently operate a bug bounty programme.
Submitting a vulnerability report does not create an entitlement to financial compensation or other reward.
TP Silva Oy may, at its discretion and with the reporter’s consent, acknowledge individuals or organisations that have responsibly reported significant vulnerabilities.
12. Contact
Security vulnerabilities affecting TP Silva Oy products should be reported to:
TP Silva Oy
Tampere, Finland
Email: security@tpsilva.fi
This is TP Silva Oy’s single point of contact for reporting product security vulnerabilities affecting products and services supplied under the Japa, Palax, Hakki Pilke and X Firewood Factory brands.
For general product support, spare parts, sales or other non-security-related enquiries, please use the normal customer service channels.
Version: 1.0
Last updated: September 2026