Coordinated Vulnerability Disclose Policy

F&J Specialty Products, Inc. is committed to the secure design, development, and lifecycle management of our products. We encourage responsible reporting of potential cybersecurity vulnerabilities and follow a Coordinated Vulnerability Disclosure (CVD) approach consistent with the EU Cyber Resilience Act (Regulation (EU) 2024/2847).

How to Report a Vulnerability

If you believe you have discovered a potential security vulnerability in any F&J product, service, or digital component, please contact us at:

security@fjspecialty.com

Please include, when available:

• Description of the suspected vulnerability

• Product name, model, and software/firmware version

• Steps to reproduce

• Any supporting evidence or logs

Our Commitments

• Acknowledge receipt of the report

• Assess and validate the information

• Coordinate remediation activities

• Provide updates to the reporter as appropriate

• Fulfill all reporting obligations to EU authorities under the Cyber Resilience Act

Response timeline: Initial Screening (within 24 hours), Evaluation (within 72 hours) and Final Report (14 days from corrective measure is available)