Coordinated Vulnerability Disclosure

At ISO-Gruppe we take the security of our products, services, and users seriously. We value responsible vulnerability reporting and welcome reports from security researchers, customers, partners, and other third parties acting in good faith.

This Coordinated Vulnerability Disclosure Policy explains how to report potential security vulnerabilities to us, what you can expect from us during the process, and what we ask from you in return. Our goal is a trustworthy, confidential, and coordinated process that reduces risk for customers and users.

What you can expect from us

We welcome clear and constructive communication throughout the disclosure process.

We will review incoming reports to the best extent possible, including reports relating to vulnerabilities that may already have been remediated, in order to verify relevance, identify potential recurrence, and improve our security processes.

We review vulnerability reports through an internal assessment process designed to reduce the risk of valid reports being missed or dismissed incorrectly.

Enquiries about the status of a reported vulnerability are welcome.

When you report a potential vulnerability to us in good faith and in line with this Policy, you can expect the following:

  • We will treat each incoming vulnerability report as confidential to the extent permitted by applicable law. This does not apply to information that must be disclosed as part of the coordinated public disclosure of the vulnerability.
  • We will not disclose your personal data to third parties without your explicit consent unless we are legally required to do so.
  • We will respond to each new vulnerability report, and to each substantive update to an existing report.
  • We will remain available as a contact for a trustworthy exchange throughout the coordinated vulnerability disclosure process.
  • We will not require you to sign a non-disclosure agreement as a condition for submitting or discussing a vulnerability report.
  • We recommend that confidential information be submitted via encrypted and digitally signed email. Our public key and machine-readable reporting information are published in our security.txt.
  • We will not pursue criminal charges against you solely for reporting a vulnerability, provided that you act in good faith, comply with this Policy, and do not pursue recognizable criminal intentions or malicious conduct.

If you make a good-faith effort to comply with this policy during your security research, ISO-Gruppe will consider your research to be authorized, work with you to understand and resolve the issue quickly and will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known.

Scope

This Policy applies to:

  • Products with digital elements manufactured, developed, distributed, or maintained by ISO-Gruppe
  • Related software, firmware, APIs, cloud services, update services, and support systems under our control
  • Other systems explicitly listed as in scope on this page or on our product security pages

Unless explicitly stated otherwise, this Policy does not apply to:

  • General corporate IT infrastructure
  • Third-party systems that we do not control
  • Customer systems identifiable through customer-specific IP ranges, domains, tenants, or other identifiers
  • Issues that are solely availability complaints, support requests, or feature requests without a security Relevance

If your report concerns a customer-operated system, please contact the respective customer directly, unless you have reason to believe that the vulnerability is caused by a product or service provided by ISO-Gruppe.

How to report a vulnerability

Please report suspected vulnerabilities through one of the following channels:

For confidential information, we strongly recommend using encrypted and digitally signed email.

To help us assess and triage your report, please include, where possible:

  • Affected product, service, component, URL, or interface
  • Affected version or build
  • Clear description of the issue
  • Potential security impact
  • Step-by-step reproduction instructions
  • Proof of concept, logs, screenshots, request/response samples, or other relevant evidence
  • Your contact details, if you want us to respond directly

Reports may also be submitted anonymously, but this may limit our ability to coordinate with you. To support efficient handling of your report, please provide at least one valid contact option for follow-up questions and coordination.

Response procedure

We aim to handle reports quickly and transparently. Unless exceptional circumstances apply, you can expect the following response procedure:

  • Acknowledgement of receipt: within 5 business days
  • Initial triage response: following preliminary assessment of your report
  • Response to substantive updates to an existing report: if applicable
  • Status updates during active handling: depending on duration of processing

If a case is unusually complex or depends on third parties, we will let you know and continue to provide periodic updates.

If you do not receive an acknowledgement from us within the response time stated above, please contact us again or use an alternative reporting channel. In rare cases, technical delivery or processing issues may prevent a report from reaching us or being handled correctly.

What we ask from you

We ask that you:

  • Act in good faith.
  • Avoid privacy violations, service degradation, disruption, destruction, or manipulation of data.
  • Test only to the extent necessary to confirm the existence of the vulnerability.
  • Do not exfiltrate data, establish persistence, or pivot to other systems.
  • Stop testing and notify us immediately if you unintentionally access sensitive data.
  • Hive us a reasonable opportunity to validate and remediate the issue before public disclosure.
  • Do not engage in extortion, blackmail, social engineering, or other unlawful conduct.

We expect all communication related to vulnerability reporting to remain respectful and professional. Discriminatory, abusive, threatening, or insulting behavior is not acceptable from any party involved in the process.

Coordinated disclosure

If a reported issue is confirmed as a vulnerability, we will seek to coordinate disclosure in a way that reduces risk to customers and users.

Depending on the case, coordinated disclosure may include:

  • A security advisory
  • Remediation guidance
  • Workaround or mitigation information
  • Information on affected versions and fixed versions
  • Acknowledgement of the reporting entity, where requested and agreed

We may decide to accelerate public disclosure where customer protection, active exploitation, legal obligations, or public safety require it.

Legal notice

This Policy does not authorize actions that are unlawful, unsafe, or disproportionate. In particular, this Policy does not authorize:

  • Denial-of-service testing
  • Destructive testing
  • Unauthorized access beyond what is necessary to demonstrate the issue
  • Copying, modification or deletion of data
  • Making changes to the system
  • Repeated access to the system or sharing access to the system with others
  • Malware deployment
  • Physical attacks
  • Phishing or social engineering
  • Performing brute-force attacks to gain access to a system

If you are unsure whether a test is safe or in scope, contact us first.

Questions

Questions about this Policy may be sent to security@iso-gruppe.com.

Contact