Vulnerability Disclosure
You have found a vulnerability in one of our products and want to report it.
First of all, thank you!
Please use the contact email address shown below. Mails can be sent PGP-encrypted.
Please also refer to the information about what happens with your submission below.
Contact
Email: psirt@rhd-instruments.de
Download our PGP Key (60A7 2F75 FC23 63B0 8DD4 8AEF CE58 B128 762A 1EFF)
The link includes a predefined email body. Alternatively, please include at least the following information:
- Which product is affected
- Which versions or revisions are affected (if known)
- What type of vulnerability is it
- A description of the vulnerability, as detailed as possible
Your contact details are optional.
What happens with your submission
We treat your submission as highly sensitive data. To ensure data safety, we establish strict rules:
- Incoming mails are stored on a mailserver by Strato AG in Germany
- All mails are deleted as soon as the incident is resolved
- Only the minimum number of people required to handle your submission at rhd instruments have access to the mail
- Upon submission, you will receive an automated response as a notice of receipt
- You will receive a response from the rhd team within five business days
- Your contact details or other personal information will not be shared with any third party unless explicitly required by law
Incident handling
After receiving your incident, the rhd team will work on validating the vulnerability, assessing affected customers and developing a fix.
If required, the vulnerability will be reported to official vulnerability platforms such as ENISA / SRP.
A security update will be made available to the affected customers as required by the specific vulnerability, and it will be published on our website.
The timespan for development of the fix and publication will be based on the urgency of the vulnerability in quest.
Rewards
At this time rhd instruments does not offer a bug bounty program.
It is your choice, if you want to be acknowledged in the public disclosure.