Request a quote
Vulnerability reporting

Security and vulnerability reporting

Did you find a security flaw on our website, in the licence server or in our software? Write to us. We take every report seriously and are grateful for it.

How to report a vulnerability

Send us an e-mail with “Security” in the subject. The message should contain:

  • a description of the vulnerability and its impact,
  • the affected address, function or product version,
  • steps to reproduce the problem (a short description or a sample request is enough),
  • a contact we can reply to.

benesl@benesl-automation.cz

Please do not send us other people’s personal data or data obtained by exploiting the vulnerability; a minimal demonstration is enough to prove the problem. If you need to send sensitive material encrypted, say so in your first message and we will agree on how to exchange it.

The same contact is also published in machine-readable form in the file /.well-known/security.txt.

What to expect

  • We usually confirm receipt of a report within 3 working days.
  • Within 14 days we will tell you how we assessed the report and what happens next.
  • We fix vulnerabilities according to severity and will keep you informed about the date of the fix.
  • We will agree on disclosure with you. If you wish, we will credit you in the acknowledgements.

What is in scope

Reports may concern:

  • the website benesl-automation.cz including the licence portal and the interface at licence.benesl-automation.cz,
  • the TIA MCP software (installation package, updates, licensing, remote mode and OAuth sign-in),
  • the BaLib libraries and the BAVIS application from Benešl Automation.

Out of scope:

  • third-party services (Cloudflare, Stripe, iDoklad, e-mail services), which please report directly to their operators,
  • vulnerabilities in Siemens products (TIA Portal, PLCs, Openness), which belong with Siemens ProductCERT,
  • denial-of-service attacks (DoS), spam, social engineering and physical attacks.

Guidelines for researchers

If you act in good faith, follow these guidelines and give us a reasonable time to fix the issue, we will not treat your report as an attack and will not take legal action because of it. We therefore ask you to:

  • test only your own accounts and data,
  • do not disrupt the availability of the service or other customers’ data,
  • do not disclose the vulnerability before we have agreed on a date.

How we secure the service

  • The website and the licence server use HTTPS with HSTS and send security headers.
  • Card payments are processed by Stripe; your card details never reach us.
  • Licences are digitally signed and TIA MCP verifies them offline.
  • TIA MCP runs locally on your computer. Every write to the project is backed up first, and downloading to a real PLC is disabled by default.
  • We back up the licence and order records daily to private storage and monitor the service automatically.

Security updates

We release fixes as regular TIA MCP updates. The application checks once a day whether a new version is available (the check can be turned off).

Overview of changes in each version

Page last updated: 8 October 2026.