/en/products-services/accessories /en/products-services/products

Cybersecurity at KRÜSS

The security of our products, software and digital services is important to KRÜSS. We assess cybersecurity risks and process reported vulnerabilities through a structured procedure.

 

This page provides information on reporting potential vulnerabilities

How we handle cybersecurity

KRÜSS considers cybersecurity across the lifecycle of its products, software and digital services. Reports of potential vulnerabilities are recorded by the responsible internal units, assessed technically and handled according to the identified risk.

 

We welcome responsibly submitted vulnerability reports and aim for transparent, constructive communication with the people who report them.

Step 01: Intake

Your report is recorded and documented by the responsible internal units.

Step 02: Technical assessment

We review reproducibility, the affected area and the resulting risk.

Step 03: Risk-based handling

Confirmed vulnerabilities are handled according to their risk and disclosed in a coordinated manner.

Scope for reports

Reports may relate in particular to the following areas.

01: KRÜSS products

02: Software and firmware

03: Web and cloud services

04: The KRÜSS website

05: The KRÜSS IT infrastructure

06: Integrated third-party components where they form part of a KRÜSS product

Not for support requests

This reporting channel is intended exclusively for potential cybersecurity vulnerabilities. For general product questions, application support, repairs or other service requests, please use our regular contact and support channels.

 

Go to contact and support

Coordinated Vulnerability Disclosure Policy

Our Coordinated Vulnerability Disclosure Policy describes how potential vulnerabilities can be reported to KRÜSS, which information we need for our investigation, and which rules apply to coordinated disclosure.

 

View CVD Policy

Contact and reporting

Report a potential vulnerability by email

Please encrypt confidential information with our public OpenPGP key where possible and verify the fingerprint first. Where a return channel is available, we acknowledge receipt within five working days.

Send your report to: security@kruss.de