At ISO-Gruppe we take the security of our products, services, and users seriously. We value responsible vulnerability reporting and welcome reports from security researchers, customers, partners, and other third parties acting in good faith.
This Coordinated Vulnerability Disclosure Policy explains how to report potential security vulnerabilities to us, what you can expect from us during the process, and what we ask from you in return. Our goal is a trustworthy, confidential, and coordinated process that reduces risk for customers and users.
We welcome clear and constructive communication throughout the disclosure process.
We will review incoming reports to the best extent possible, including reports relating to vulnerabilities that may already have been remediated, in order to verify relevance, identify potential recurrence, and improve our security processes.
We review vulnerability reports through an internal assessment process designed to reduce the risk of valid reports being missed or dismissed incorrectly.
Enquiries about the status of a reported vulnerability are welcome.
When you report a potential vulnerability to us in good faith and in line with this Policy, you can expect the following:
If you make a good-faith effort to comply with this policy during your security research, ISO-Gruppe will consider your research to be authorized, work with you to understand and resolve the issue quickly and will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known.
This Policy applies to:
Unless explicitly stated otherwise, this Policy does not apply to:
If your report concerns a customer-operated system, please contact the respective customer directly, unless you have reason to believe that the vulnerability is caused by a product or service provided by ISO-Gruppe.
Please report suspected vulnerabilities through one of the following channels:
For confidential information, we strongly recommend using encrypted and digitally signed email.
To help us assess and triage your report, please include, where possible:
Reports may also be submitted anonymously, but this may limit our ability to coordinate with you. To support efficient handling of your report, please provide at least one valid contact option for follow-up questions and coordination.
We aim to handle reports quickly and transparently. Unless exceptional circumstances apply, you can expect the following response procedure:
If a case is unusually complex or depends on third parties, we will let you know and continue to provide periodic updates.
If you do not receive an acknowledgement from us within the response time stated above, please contact us again or use an alternative reporting channel. In rare cases, technical delivery or processing issues may prevent a report from reaching us or being handled correctly.
We ask that you:
We expect all communication related to vulnerability reporting to remain respectful and professional. Discriminatory, abusive, threatening, or insulting behavior is not acceptable from any party involved in the process.
If a reported issue is confirmed as a vulnerability, we will seek to coordinate disclosure in a way that reduces risk to customers and users.
Depending on the case, coordinated disclosure may include:
We may decide to accelerate public disclosure where customer protection, active exploitation, legal obligations, or public safety require it.
This Policy does not authorize actions that are unlawful, unsafe, or disproportionate. In particular, this Policy does not authorize:
If you are unsure whether a test is safe or in scope, contact us first.
Questions about this Policy may be sent to security@iso-gruppe.com.