The security of our products and systems is our highest priority. If you identify a potential security vulnerability, weakness, or cybersecurity incident related to our products or software solutions, we ask that you report it to us through this reporting channel.
With your support, we can identify potential risks at an early stage, assess them, and take appropriate measures to protect our customers and users.
What can be Reported Here?
Please use this reporting channel in particular for information regarding:
- Security vulnerabilities in our products, systems, or software solutions
- Weaknesses that could lead to unauthorized access to systems or data
- Active exploitation of a vulnerability
- Cybersecurity incidents affecting the confidentiality, integrity, or availability of our products or systems
- Findings from security assessments, penetration tests, or responsible disclosure activities
What Information Helps Us Process Your Report?
Please describe your observation in as much detail as possible. The following information is particularly helpful:
- Affected product or system
- Product version or software release
- Description of the vulnerability or incident
- Date and time of discovery
- Steps to reproduce the issue (if possible)
- Potential impact
- Screenshots, log files, or other technical information
Severity Classification
If you are familiar with CVSS v3.1, please include the severity of the vulnerability in your report as a CVSS vector string (CVSS Calculator). If you are unsure how to assess the vulnerability, please indicate this in your report.
Responsible Disclosure
We kindly ask you to report discovered vulnerabilities confidentially through this reporting channel and to refrain from disclosing this information to third parties until a coordinated disclosure has taken place.
Upon receipt of your report, we will acknowledge it within 7 calendar days. We aim to assess reported vulnerabilities within 90 calendar days and implement appropriate remediation measures.
This enables us to review the report, assess the associated risks, and, where necessary, develop and provide suitable mitigations or fixes.
Our goal is the coordinated and responsible handling of security vulnerabilities in the best interests of all users, customers, and partners.
Confidential Handling
All reports received will be treated confidentially and used solely for the assessment and handling of the reported issue. We carefully review every report and take appropriate action where necessary.
Anonymous Reports
You may also submit reports anonymously. Please note, however, that in such cases we are unable to ask follow-up questions or provide updates regarding the processing status, the outcome of our assessment, or the remediation of identified vulnerabilities. For efficient processing, we therefore recommend that you provide a means of contact.
Important Notice
This reporting channel is intended exclusively for the reporting of security vulnerabilities and cybersecurity incidents. For general service, support, or sales inquiries, please use the relevant contact options available on our website.
In addition to the contact form, you can also reach us by telephone or email:
Phone: +49 4298 922-333
Email: product_security@nabertherm.de