Send vulnerability reports to security@motionsystems.eu. This is the single reporting address for security issues in Motion Systems products. Reports may be written in English or Polish.
Please do not report a security issue through a public issue tracker, a forum or the general contact form. Those channels are visible to more people than need to see an unpatched issue.
A vulnerability can also be reported through a CSIRT designated as coordinator, including anonymously, instead of directly to us. In Poland that is CSIRT NASK.
A report we can reproduce is easier to assess. As much of this as you have:
- The product and version. Application version, firmware build or hardware model. In our desktop software the version is in the "About" window.
- Steps to reproduce, in order.
- What happened, and what an attacker gains: data, access or control they should not have.
- Any sign the issue is already being exploited, and what that sign was. This changes how quickly we and the authorities have to act, so tell us even if you are unsure.
- Where you tested - your own equipment, or a system belonging to someone else with their permission.
This policy covers products manufactured by Motion Systems, including but not limited to our motion platforms and their controllers, the firmware running on them, the MotionBox, the ForceSeatPM Manager desktop application, the ForceSeatDI SDK and API, and this website. It applies regardless of the brand a given unit was sold under, including Qubic System.
Vulnerabilities in third-party components we ship are in scope as well. Report them here rather than only upstream, so we can track the affected versions and get a fix to our users.
- 01Assessment. Reports are assessed to determine whether the issue is confirmed and which products are affected.
- 02Remediation. Where an issue is confirmed, a fix is prepared and released.
- 03Publication. An advisory is published on this page after the fix is available, describing the issue, the affected products and versions, the impact and severity, and what you need to do to remediate it.
In rare cases we may delay publication where releasing the details would put users at more risk than it removes, for instance where a fix cannot yet reach every affected unit.
Where EU law requires it, an actively exploited vulnerability or a severe incident affecting the security of one of our products is notified to the relevant CSIRT and to ENISA within the deadlines set by that law.
We ask that you do not disclose the issue publicly until a fix has been made available. When testing, we also ask that you:
- stay within your own equipment and accounts, and do not access other people's data;
- take no more data than is needed to demonstrate the issue, and delete it afterwards;
- do not degrade, disrupt or take down a service other people are using;
- do not run automated scanners against our sites, do not attempt denial of service, and do not target our staff, our partners or our suppliers through social engineering or physical access.
We do not run a paid bug bounty and do not offer rewards for reports.
Advisories for fixed vulnerabilities are published here. No advisories have been published to date.
Motion Systems Michał Stanek
Miedziana 7, 55-003 Nadolice Wielkie, Poland
security@motionsystems.euWe process the contact details in your report to handle it and to meet our obligations under EU law. How we handle personal data is described in our privacy policy.
Policy last reviewed 2 September 2026. Machine-readable contact details are published at /.well-known/security.txt. For anything that is not a security issue, use the contact page.