As a responsible manufacturer of products with digital elements, we take the security of our products and the protection of our users very seriously. In accordance with the European Cyber Resilience Act (CRA), we have established this policy to provide security researchers and users with a clear, secure, and transparent way to report potential security vulnerabilities.
How to report a vulnerability
If you have discovered a security vulnerability in one of our products or services, we ask that you notify us immediately.
- Preferred reporting method: Send an email to
This email address is being protected from spambots. You need JavaScript enabled to view it. - Languages: We accept reports in German and English.
What your report should include
To enable our IT security team to validate and remediate the vulnerability as quickly as possible, your report should include the following information:
- The affected product, including the exact software/firmware version.
- A detailed description of the vulnerability and its potential impact.
- Clear step-by-step instructions (or a proof-of-concept script) for reproducing the issue.
Our commitment to you (handling of reports)
We are committed to a fair, transparent, and prompt process:
- Acknowledgement of receipt: We will acknowledge receipt of your report within 48 hours (on business days).
- Validation & status updates: We will assess the vulnerability and keep you regularly informed of significant progress regarding its remediation. • Transparent remediation: As soon as a security update (patch) is available, we will release it along with a transparent description of the addressed vulnerability (including the CVE identifier, if applicable).
Safe Harbor Principles
If you act in good faith when discovering and reporting a vulnerability, we assure you of the following:
- No legal action: We will not initiate or pursue civil or criminal legal action against you (e.g., allegations of unauthorized data access) provided that you have not damaged our systems, have not exfiltrated data, and have reported the vulnerability directly to us.
- Confidentiality: We will treat your identity with strict confidentiality and will not disclose your data to third parties without your explicit consent, unless we are legally required to do so (e.g., to national CSIRTs/BSI or ENISA).
- No premature disclosure: In return, we expect you not to publicly disclose details of the vulnerability before we have had the opportunity to provide a corresponding security update, so as not to put our users at risk.
Validity
Krempien+Petersen Qualitäts-Kontrollsysteme GmbH reserves the right to change this policy at any time in compliance with the valid laws.
Hamburg, 2026-10-01
