Passer au contenu principal Passer à la recherche Passer à la navigation principale
Mo. - Do. 8:00 - 16:45 Uhr, Fr.: 8:00 - 15:00 Uhr

CVD-Policy



Coordinated Vulnerability Disclosure Policy

Langer + Laumann supports the responsible and coordinated disclosure of vulnerabilities.


Scope

This policy applies to vulnerabilities affecting Langer + Laumann products, software, firmware, digital services, or IT infrastructure.

Automated scan results sould be supplemented with verifiable technical information. Scan reports that cannot be independently verified may not be eligible for a qualified assessment.


Our commitments

If you report a potential vulnerability in good faith and in accordance with this policy, we commit to the following:

  • We will treat your report confidentially.
  • We will remain available as you point of contact throughout the handling of the report.
  • We will not require a confidentiality agreement as a prerequisite for processing the report.
  • We will not initiate criminal proceedings against you, provided that you act without any apparent intent to cause harm and comply with this policy.
  • At your request, we will acknowledge your contribution after the process has been completed, provided that there are no security or confidentiality reasons not to do so.


Responsible conduct

When investigating and reporting a vulnerability, please observe the following:

  • Do not exploit the vulnerability beyond what is necessary to demonstrate it.
  • Do not modify, delete, or publish any data.
  • Do not access data or systems belonging to third parties.
  • Do not carry out social engineering, spam, brute-force, or denial-of-service attacks.
  • Stop your investigation as soon as you encounter personal or confidential data.
  • Do not make technical details public until publication has been coordinated with us.

Reports will also be reviewed if individual provisions of this policy have not been fully complied with. The nature and scope of any further action will be determined on a case-by-case basis.




Disclosure of vulnerabilities

Where possible, we will coordinate the disclosure of a confirmed vulnerability with the reporting person.

As a general rule, we publish validated and verified vulnerabilities within 90 days. If remediation is not reasonably possible within this period, the deadline may be extended in coordination with the responsible national CSIRT.

In cases involving active exploitation, a significant threat, or statutory reporting obligations, different measures and deadlines may be required.



Closing the process

The process is considered closed in particular if:

  • the report proves to be unfounded,
  • the vulnerability has been remediated or adequately mitigated and disclosed; or
  • required follow-up questions have remained unanswered for a period of at least 30 days, making any further investigation impossible.

Last updated 11. September 2026

_INNER_
added