Product Security
Information on product security and reporting
potential security vulnerabilities.
Would you like to report a potential security vulnerability?
Please use our contact form to report any potential security vulnerabilities or security-related issues in our products and software solutions. Our team will review your report and contact you for further information if necessary.
Please describe the potential vulnerability in as much detail as possible and specify the affected product and version.
Contact information
Technical Software Engineering Plazotta GmbH
Hopfenstr. 30
85283 Wolnzach
Germany
* Fields marked with an asterisk are mandatory.
Coordinated Vulnerability Disclosure Policy
Technical Software Engineering Plazotta GmbH places great importance on the security of its products and software solutions. Despite careful development, testing, and quality assurance, security vulnerabilities cannot be completely ruled out.
If you discover a potential security vulnerability in one of our products or software solutions, please notify us. Coordinated disclosure allows us to investigate the vulnerability, take appropriate action, and protect affected users.
Please note when conducting the examination and filing the report
- Do not exploit a identified vulnerability beyond what is necessary for its identification and documentation.
- In particular, avoid unnecessarily retrieving, modifying, deleting, or sharing data, as well as uploading or executing malicious code.
- Do not take any actions that could impair the availability or functionality of our products, systems, or services.
- Do not carry out social engineering, phishing, spam, denial-of-service, or similar attacks.
- Do not access personal, confidential, or otherwise protected information unless it is necessary to demonstrate the vulnerability.
- Please provide us with sufficient information so that we can understand, reproduce, and evaluate the reported vulnerability.
- Do not disclose information about a potential vulnerability to third parties or make it public before a coordinated disclosure has taken place.
If, in the course of your investigation, you inadvertently access personal, confidential, or otherwise protected information, or if you have inadvertently made changes to data or systems, please stop what you are doing immediately and notify us.
Handling Your Report
We review incoming reports and assess whether a security vulnerability exists and which products, versions, or systems are affected.
If you have provided contact information, we will confirm receipt of your report and may contact you if we have any questions. For confirmed vulnerabilities, we will take appropriate measures to resolve them or mitigate the risk, depending on their severity.
Reports are always treated confidentially. Personal data is processed in accordance with our privacy policy.
Compliance with this policy does not limit the legal rights of Technical Software Engineering Plazotta GmbH. In particular, we reserve the right to conduct a legal review if a vulnerability is exploited in an abusive manner, used beyond what is necessary to demonstrate its existence, or if the principles outlined above have been violated.
Coordinated publication
If you intend to publish information about a reported vulnerability, please let us know when you submit your report or as soon as possible.
We would like to coordinate the disclosure of a confirmed vulnerability with you whenever possible. To protect our customers and users, we ask that you refrain from publicly disclosing information about a potential vulnerability or sharing it with third parties before we have had the opportunity to investigate the vulnerability, provide appropriate measures to fix it or mitigate the risk, and, if necessary, notify affected users.
Whenever possible, the disclosure by the reporting party and the corresponding security advisory from TSEP should be coordinated in terms of timing.