Coordinated Vulnerability Disclosure Policy
KRÜSS is committed to the security of its products, software, services, and IT infrastructure. We use a Coordinated Vulnerability Disclosure process for reports of potential cybersecurity vulnerabilities. The process is guided by the Cyber Resilience Act, BSI TR-03183-3, EN ISO/IEC 29147, and EN ISO/IEC 30111.
We accept reports concerning KRÜSS products with digital elements, related firmware and software, official web and cloud services, and our IT infrastructure. Reports are welcome regardless of service contract or product lifecycle.
The PDF version of this policy is authoritative. This page is provided for easier reading.
1 Good Faith Cooperation
We treat reports and personal data as confidential to the extent permitted by law. We do not require a non-disclosure agreement for submission. KRÜSS will not initiate legal action against individuals who act in good faith and comply with this policy, in particular by:
- testing only their own or expressly authorized products and systems without affecting customers;
- complying with applicable law and protect safety, privacy, measurement data, audit trails, and laboratory and production operations;
- not conducting social engineering, brute-force, denial-of-service, load or destructive testing;
- limiting testing of a potential vulnerability to the extent necessary to demonstrate it. Their own data or data expressly authorized for testing may be modified or deleted where necessary to demonstrate the vulnerability;
- stopping testing immediately upon unintended access to other data. Such data must not be modified, deleted, used or disclosed;
- deleting any personal, confidential, or non-public information obtained in the process and neither using it nor disclosing it to third parties;
- publishing technical details only after the coordinated disclosure date..
This assurance does not apply in cases of apparent criminal intent, deliberate harm, extortion, or another material breach of these rules. It does not bind third parties or authorize access to third-party systems or data.
2 Process
2.1 Reporting
Send the report, preferably encrypted, to security@kruss.de. Where a return channel is available, we acknowledge receipt within five working days. Please describe the observed and expected behavior, impact, affected product or system (including model, serial number, and version where available), and reproducible steps or a proof of concept. Automated scan results require supporting evidence. Also tell us whether the vulnerability is already public or is being actively exploited.
2.2 Analysis
We investigate and reproduce the reported vulnerability and request further information where needed. Where a return channel is available, we provide substantive feedback within ten working days or explain why the investigation needs more time and when the next update will be provided.
2.3 Resolution
We address confirmed vulnerabilities with the responsible development, service, and IT teams. The lifecycle status of the affected product may influence the available remediation. During this period, we remain in contact with the reporter where a return channel is available.
2.4 Disclosure
We address confirmed vulnerabilities based on risk. Once a security update, workaround or other appropriate remediation is available, KRÜSS publishes the necessary information in a security advisory on the KRÜSS website. The advisory includes, in particular, information on affected products and versions, impact and severity, and available updates or other remediation measures. In justified cases, publication may be deferred until affected users have had a reasonable opportunity to implement the remediation. Statutory reporting obligations to the competent authorities remain unaffected.
With the reporter's consent, KRÜSS may provide acknowledgement by name or alias. There is no entitlement to payment or reimbursement of costs; KRÜSS does not operate a bug bounty program.
Security resources
All public security addresses at a glance.
| Security-Seite | |
|
CVD-Policy |
|
| OpenPGP |
https://www.kruss-scientific.com/.well-known/security-key.asc |
| security.txt | |
| Languages | English and German |
| Further information on data protection |
https://www.kruss-scientific.com/en/data-privacy-statement https://www.kruss-scientific.com/de-DE/datenschutzerklaerung |