Product Security / Vulnerability Reporting
We take the security of our hardware and software products very seriously. If you believe you have discovered a potential security issue, please contact our product security team using the contact information provided below. For confidential information, we recommend that you encrypt your message using our public GPG key.
How to report a potential vulnerability
Please send your report to: security@ichaus.de
Public GPG Key: Security-Public-Key.asc
Fingerprint: 8400 FBCD BD68 F16B F050 B18A 64B0 A03C 5CE6 34B8
Free software to read and author PGP/GPG encrypted messages may be obtained from the internet.
Please include the following information:
– Contact information (name, company, email address).
– Affected product, part number and version.
– Detailed description of the potential vulnerability.
– Steps required to reproduce the issue.
– Potential impact and estimated severity.
– Reports, screenshots, log files, or other supporting evidence (if available).
– Information about the environment in which the issue was discovered.
– Whether the vulnerability has been disclosed to any third party.
How we handle vulnerability reports
We review all reports of potential security vulnerabilities and make reasonable efforts to investigate and resolve security issues. We follow this process:
Confirmation
We confirm receipt of the security report.
Review and Risk Assessment
We investigate the reported vulnerability, verify its validity, and assess its potential security impact.
Remediation
We develop, implement, and test an appropriate fix or mitigation.
Disclosure
We coordinate communication and disclosure activities regarding the vulnerability.