What we need from you
To help us process your report quickly, please provide:
- the product concerned, including the item number and, if known, the firmware or application version
- a description of the vulnerability and its potential impact
- the steps required to reproduce the behaviour
- your contact details in case we need to get in touch
We welcome reports in either German or English. Even an incomplete report is better than none at all. Please do get in touch rather than leaving the matter unresolved.
How we proceed
Confirmation of receipt within three working days. You will then know that your report has been received and is being processed.
Initial assessment within ten working days. We will let you know whether we have been able to reproduce the behaviour and how we assess it.
Ongoing updates. Whilst the issue is being resolved, we will keep you informed of the progress.
Publication following resolution. We publish details of resolved vulnerabilities in this section of our website so that operators of our devices can take action.
Credits on request. If you wish, we will credit you as the discoverer in the publication. If you prefer to remain anonymous, we will respect that too.
Please allow us time to rectify the issue before making any details public. As a guideline, we suggest 90 days from the date of your report. If a vulnerability is being actively exploited or if the fix takes longer, we will discuss the timing with you.
What we ask of you
To ensure that a well-intentioned test does not cause any harm:
- Please only carry out tests on devices and systems that you own or for which you have explicit permission.
- Do not access, alter or delete other people’s data.
- Refrain from denial-of-service tests, social engineering, phishing and physical attacks on our premises or staff.
- Do not disclose any details until you have consulted with us.
If you adhere to these rules, we will regard your report as a contribution to the security of our products and will not take any legal action against you. We make this commitment on our own behalf. We cannot speak on behalf of third parties or regarding decisions made by law enforcement agencies.
No bug bounty programme
We do not currently pay rewards for vulnerability reports. What we do offer is a thorough investigation, reliable feedback and, upon request, recognition as the discoverer.