Coordinated Vulnerability Disclosure Policy (VDP)
Arturia

September 2026

Introduction: Security Commitment & Quality Assurance

At Arturia, our passion for musical innovation goes hand in hand with a fundamental commitment: ensuring the integrity of our creations, the security of our users, and the resilience of our digital ecosystem. From hardware instruments to virtual suites, as well as our distribution platforms such as the Arturia Software Center (ASC), security is integrated by design (Secure by Design) and maintained throughout the entire product lifecycle. As part of our continuous Quality improvement initiative and in alignment with the requirements of the European Union's Cyber Resilience Act (CRA), we collaborate closely with the global security research community and independent experts. This policy defines the institutional, legal, and technical framework of this collaboration.

1. General Principles and Quality Assurance

The trust of our artists, studios, and partners relies on the dependability of our software and hardware equipment. Our Coordinated Vulnerability Disclosure (CVD) policy aims to provide a structured, transparent, and secure channel to identify and remediate any software or hardware flaws before they can be exploited for malicious purposes. We view every legitimate disclosure not as an operational constraint, but as a strategic opportunity to elevate our R&D engineering standards and safeguard our intellectual property over the long term.

Arturia formally commits to taking no legal action against individuals or organizations that identify and report vulnerabilities to us, provided that such research is conducted in strict compliance with the following principles:

  • Good faith and loyalty: Investigations must solely aim to improve the security of our products and systems, without intent to cause harm, bypass licensing mechanisms abusively, or commit extortion.
  • Data confidentiality: No personal data, commercial data, or intellectual property belonging to Arturia or its customers may be accessed, modified, exfiltrated, or disclosed.
  • Service continuityTesting must under no circumstances disrupt the availability, integrity, or performance of our web infrastructure, cloud services, or user hardware equipment.
  • Coordinated disclosureYou agree to afford us a reasonable timeframe to qualify and remediate the issue prior to any public disclosure or external communication.
  • If these conditions are strictly met, Arturia will consider your research authorized, legal, and beneficial to our overall ecosystem.

3. Scope of Application

To ensure operational integrity and clear risk evaluations, the authorized scope for security testing is strictly defined.

CategoryIn-Scope Components
Software EcosystemArturia Software Center (ASC), virtual suites (V Collection, FX Collection, Pigments), and associated system utilities.
Hardware & FirmwareEmbedded systems, firmware, and communication protocols across all hardware product lines (synthesizers, MIDI controllers, audio interfaces).
Online ServicesWeb infrastructure, e-commerce platforms, and APIs hosted under the primary domain *.arturia.com.
Strictly Prohibited Activities (Out-of-Scope)
  • Denial of Service (DoS / DDoS) attacks intended to interrupt service availability.
  • Social engineering, phishing, or impersonation targeting Arturia employees, partners, or customers.
  • Destruction, alteration, exfiltration, or publication of real customer or operational data.
  • Physical attacks against our facilities, server rooms, manufacturing lines, or corporate networks.
  • Submissions of theoretical vulnerabilities without a usable or demonstrable Proof of Concept (PoC).

4. Secure Reporting Procedures

To submit a vulnerability report to our R&D and Security teams, you must use our official dedicated channel:

📩 Contact Address: security@arturia.com

🔒 Encryption Requirement (PGP): To protect the confidentiality of discovered flaws during transit, any message containing technical exploitation details, PoCs, or code snippets must strictly be encrypted using our official PGP public key.

👉 [Download Link: Arturia Public PGP Key - Official Fingerprint: XXXX XXXX XXXX XXXX XXXX]

Recommended Report Structure:

  • Description of the Flaw: Nature of the vulnerability and potential impact on software, service, or hardware equipment.
  • Exact Scope: Product name, version number (firmware or software), affected environment, or URL.
  • Reproduction Steps: Detailed step-by-step instructions, attack scenario, or demonstration script enabling our engineers to independently verify the issue.

5. Internal Handling Process and Service Level Agreements (SLA)

Upon receipt of a valid submission at security@arturia.com, the report is immediately triaged by our Product Security Incident Response Team (PSIRT). We adhere to the following operational timeline:

StageTarget SLAAction / Commitment
1. Acknowledgment48 business hoursConfirmation of report receipt and assignment of an internal tracking ticket.
2. Evaluation & Qualification5 business daysTechnical qualification of severity utilizing the CVSS v4.0 standard framework.
3. RemediationOngoing trackingPrioritization within the R&D backlog and routine progress updates to the researcher.
4. Regulatory EscalationWithin 24 hours (if required)Mandatory legal notification to ENISA and CERT-FR in the event of active exploitation risks (CRA).

6. Technical Specifications & Metadata

In alignment with international web security standards (RFC 9116), the directives of this policy are also published in machine-readable format at:

https://www.arturia.com/.well-known/security.txt


Copyright © 2026 Arturia All rights reserved.