The security of our products and of our own IT is an integral part of how we develop and operate. This page contains everything you need in order to report a vulnerability to us, to follow our security advisories and to reach our security organisation.
If you have found a possible security vulnerability in one of our products, in our software or in our publicly accessible infrastructure, please report it to us directly:
| E-Mail: | security[at]klotz[dot]de |
| PGP key | https://www.klotz.de/pgp-key.txt |
| Availability | Mon–Fri, 08:00–17:00 (CET/CEST), except on public holidays in Bavaria |
| Languages | Deutsch, Englisch |
This address is our single point of contact for all security-related reports concerning our machines and the software running on them.
These contact details are also published in our security.txt in accordance with RFC 9116.
Please do not report security vulnerabilities through general support, the contact form or social media.
Für Schwachstellenmeldungen bitten wir um verschlüsselte Übermittlung. Unseren PGP-Schlüssel finden Sie unter www.klotz.de/pgp-key.txt. Verschlüsseln Sie insbesondere technische Details, Proof-of-Concept-Code, Log-Auszüge und Angaben zu betroffenen Anlagen.
If encryption is not possible for you, please contact us first without encryption and without technical details. We will then agree a secure channel with you at short notice. An unencrypted report is always preferable to no report at all.
Anonymous reports are possible. In that case, however, we cannot ask follow-up questions or keep you informed of progress.
We currently do not operate a bug bounty programme; reports are not remunerated.
Please observe the following principles during your research:
Welcome
Not permitted
In scope
Out of scope
Reports are processed by our Product Security Incident Response Team (PSIRT) following a defined process:
Where a public identifier (CVE) is appropriate for a vulnerability, we arrange for it to be assigned through the responsible body. Actively exploited vulnerabilities and severe security incidents are reported to the competent authorities within the statutory deadlines.
We publish remediated vulnerabilities in our products together with the corresponding security update:
An advisory contains as a minimum: affected products and versions, a description of the vulnerability, its impact, its severity, the available fix and, where applicable, interim measures.
For customers with automated vulnerability management, we are evaluating additional provision in machine-readable form. Please contact us if you have a requirement.
Please notify us of any changes to your contacts so that security information reaches the right people.
Provision of updates: We provide security updates. For machines without a network connection, updates are supplied as a signed offline package with a checksum and installation instructions.
Integrity: All update packages are digitally signed. We publish checksums and signatures together with the package. Please verify them before installation.
Software bill of materials (SBOM): We maintain a software bill of materials for our products in CycloneDX format. Customers can obtain the SBOM on request via security[at]klotz[dot]de or through their sales contact.
Secure operation: Guidance on secure commissioning and hardening of our machines (network segmentation, access, remote maintenance, password changes) is provided in the respective operating manual. Securing the operating environment is the responsibility of the operator.
Support period: For each of our products containing digital elements, we guarantee a support period of at least five years from the date of release. During this period, we will effectively address vulnerabilities and provide security updates free of charge. For many of our systems, a longer support period applies in line with their expected service life; you will find the specific period applicable to your product in the relevant product documentation. You can obtain information about your system’s support period at any time by contacting security[at]klotz[dot]de. Once the support period has expired, we will continue to accept reports but can no longer guarantee that a fix will be provided.
Cyber Resilience Act (Regulation (EU) 2024/2847). We manufacture custom-engineered machinery including the control and operating software running on it, and are therefore a manufacturer of products with digital elements within the meaning of the CRA. The coordinated vulnerability disclosure policy described on this page and the single point of contact for vulnerability reports form part of our obligations under the CRA and are additionally set out in the product documentation. Actively exploited vulnerabilities and severe security incidents are reported in accordance with the deadlines of the CRA (early warning within 24 hours, notification within 72 hours, final report within 14 days or one month respectively).
NIS2 / BSIG. NIS2 / BSIG. As a company we operate an information security management system whose measures are based on ISO/IEC 27001. These include risk management, incident handling, business continuity and recovery planning, access control with multi-factor authentication, cryptography and the security of our supply chain.
Where a security incident within our company may affect our customers, their machines or their data, we actively inform the affected customers through the contacts on file and, where necessary, via this page.
If you wish to report an incident affecting us as a company – for instance misuse of our name, fraudulent invoices or compromised accounts – please also use security[at]klotz[dot]de.
Security does not stop at the factory gate. From suppliers of software, components and IT services we expect:
The details are governed by contract. Questions are answered by security[at]klotz[dot]de.
In order to process your report we handle the data you submit, in particular contact details and technical information. The legal basis is Art. 6(1)(c) and (f) GDPR in conjunction with our statutory obligations regarding vulnerability handling. We retain the data for the period specified by law for record-keeping purposes. It is disclosed only where this is necessary for remediation or required by law. Further information at Privacy policy.
Administration:
Reception
Tel: +49 8221 905-0
E-Mail: info@klotz.de
Distribution:
Kristina Esch
Assistant to the sales management
Tel: +49 8221 905-565
E-Mail: sales@klotz.de
Recruiting:
Linda Kircher
Personalreferentin
Tel: +49 8221 905-577
E-Mail: karriere@klotz.de
Management:
E-Mail: info@klotz.de
*mandatory information
KLOTZ GmbH Robert-Bosch-Straße 1 | 89359 Kötz | Germany
We are your experienced partner for the development and implementation of highly complex special machines, systems and technical software in Kötz near Günzburg and in Shanghai, China.
© 2024 Copyright by KLOTZ GmbH. Site designed & programmed by metavers GmbH & Alpha Design