Vulnerability Disclosure Policy

Pfannenberg Group is committed to maintaining the security, integrity, and availability of its products, services, websites, and information systems. This Vulnerability Disclosure Policy provides security researchers, customers, partners, and other stakeholders with a responsible process for reporting suspected security vulnerabilities.

In Scope

  • Pfannenberg websites and web services

  • Cloud-based applications operated by Pfannenberg

  • Products with digital elements manufactured or distributed by Pfannenberg

  • Software and firmware developed by Pfannenberg

  • Publicly accessible network services operated by Pfannenberg

Out of Scope

  • Physical attacks

  • Social engineering

  • Denial-of-Service testing

  • Spam activities

  • Malware deployment

  • Access beyond what is necessary to validate a vulnerability

Report a Vulnerability

Security Contact

Email: compliance@pfannenberg.com

Formular:
Report a security incident via web form.

Responsible Disclosure

Researchers are requested to:

  • Avoid privacy violations

  • Avoid service interruption

  • Minimize impact on customers

  • Stop testing after validating a vulnerability

  • Refrain from public disclosure before remediation

Vulnerability Handling Process

1. Acknowledgement

Receipt of valid reports is typically acknowledged within five business days.

2. Validation

The PSIRT assesses technical validity and impact.

3. Risk Assessment

Severity and exploitability are evaluated.

4. Remediation

Corrections, updates, mitigations or compensating controls are developed.

5. Disclosure

Security advisories and customer notifications may be issued.

Coordinated Disclosure

Pfannenberg supports responsible and coordinated vulnerability disclosure. Public disclosure should occur only after remediation or mitigation measures are available, unless otherwise required by law.

Cyber Resilience Act (CRA)

For products with digital elements, Pfannenberg may investigate, document, remediate and disclose vulnerabilities as required by applicable cybersecurity regulations, including the EU Cyber Resilience Act.

Confidentiality

All vulnerability reports will be handled confidentially and used solely for validation, remediation, communication and regulatory compliance.

Recognition

Pfannenberg appreciates the contribution of security researchers. With the researcher's consent, contributions may be acknowledged in future security advisories or dedicated recognition pages.

Contact Information

Product Security Incident Response Team (PSIRT)
Pfannenberg Group

compliance@pfannenberg.com