Security Reports
What would you like to report?
We confidentially accept reports concerning potential security vulnerabilities in our products as well as security-related incidents in our IT and communications environment.
Please use the appropriate security contact for your report. Wherever possible, confidential technical information should be transmitted in encrypted form. Please do not publish information about a suspected vulnerability until further action has been coordinated with us.
Vulnerability in a product — PSIRT
Please contact our Product Security Incident Response Team (PSIRT) if you would like to report a potential vulnerability in a product, firmware, software, interface, documentation, or related process of Langer + Laumann.
Examples include:
- Vulnerabilities in firmware or software
- Insecure interfaces or communication protocols
- Bypassing authentication or access controls
- Disclosure of sensitive data by a product
PGP-Key: PSIRT-Schlüssel herunterladen
Fingerprint: C1C5B7B0B86AEFA2933A3E10746F29CE4643A594
Where possible, please use the following subject line:
[SECURITY] Product or affected component
E-Mail: psirt@lul-ing.de
Security incident at Langer + Laumann — CSIRT
Please contact our Computer Security Incident Response Team (CSIRT) if you would like to report a suspected or confirmed security incident in our IT or communications environment.
Examples include:
- Unauthorized access to systems or accounts
- Phishing or messages sent fraudulently in our name
- Loss or disclosure of confidential information
- Suspected malware or ransomware
PGP-Key: CSIRT-Schlüssel herunterladen
Fingerprint: 67AE4919B9E956DF66CC803B54B80C957EE502C7
Where possible, please use the following subject line:
[URGENT SECURITY INCIDENT] Brief description of the incident
E-Mail: csirt@lul-ing.de
In the event of an ongoing or particularly critical incident, please use the following subject line:
[URGENT SECURITY INCIDENT] Brief description of the incident
These contact options do not replace an emergency call. If there is an immediate danger to people or facilities, please also contact the responsible emergency services.
How we process your report
If you provide us with means of contact, we will process your report as follows:
- We will confirm receipt within five business days. This confirmation will be sent personally and will not be exclusively automated.
- We will review the report and assess its potential impact.
- We will provide an initial qualified response within ten business days. This response will communicate the results of our review and, where applicable, coordinate any need for further clarification.
- We will coordinate remediation and, where applicable, the publication of security information.
- Where necessary, we will involve the responsible authorities or national CSIRTs.
We treat reports confidentially. Personal data will not be disclosed to third parties without the explicit consent of the reporting person, unless we are legally required to do so.
Coordinated Disclosure
Langer + Laumann supports the coordinated disclosure of vulnerabilities. Please allow us a reasonable period of time to analyze and remediate the issue before publishing technical details.
We will coordinate the publication timeline with the reporting person. In cases involving active exploitation, a significant threat, or statutory reporting obligations, different measures and deadlines may be required.
Further details can be found in our Coordinated Vulnerability Disclosure Policy.
Privacy
Information about the processing of personal data can be found in our Privacy Information.
Further technical information
- security.txt
- Public PGP key of the PSIRT
- Public PGP key of the CSIRT
Sicherheitsmeldungen können in deutscher oder englischer Sprache eingereicht werden.