Technology meets future.

Security

Security

The security of our products and of our own IT is an integral part of how we develop and operate. This page contains everything you need in order to report a vulnerability to us, to follow our security advisories and to reach our security organisation.

 

1. Reporting a vulnerability

If you have found a possible security vulnerability in one of our products, in our software or in our publicly accessible infrastructure, please report it to us directly:

E-Mail:security[at]klotz[dot]de
PGP keyhttps://www.klotz.de/pgp-key.txt
AvailabilityMon–Fri, 08:00–17:00 (CET/CEST), except on public holidays in Bavaria
LanguagesDeutsch, Englisch

This address is our single point of contact for all security-related reports concerning our machines and the software running on them.

These contact details are also published in our security.txt in accordance with RFC 9116.

Please do not report security vulnerabilities through general support, the contact form or social media.

Encrypted submission

Für Schwachstellenmeldungen bitten wir um verschlüsselte Übermittlung. Unseren PGP-Schlüssel finden Sie unter www.klotz.de/pgp-key.txt. Verschlüsseln Sie insbesondere technische Details, Proof-of-Concept-Code, Log-Auszüge und Angaben zu betroffenen Anlagen.

If encryption is not possible for you, please contact us first without encryption and without technical details. We will then agree a secure channel with you at short notice. An unencrypted report is always preferable to no report at all.

Information that helps us

  • Affected product, model or software including version or serial number
  • Description of the vulnerability and its possible impact
  • Reproducible steps (proof of concept, logs, screenshots)
  • Your assessment of the severity, ideally including a CVSS vector
  • Whether the vulnerability is already known elsewhere or has been published
  • Your contact details and whether you wish to be credited by name in the advisory

Anonymous reports are possible. In that case, however, we cannot ask follow-up questions or keep you informed of progress.

2. What you can expect from us

  • Acknowledgement of receipt within 3 working days
  • First substantive response within 10 working days
  • Status update at least every 14 days for as long as the case remains open
  • We will inform you before we publish an advisory and will credit you as the finder on request
  • We will take no legal action against you as long as you observe the rules set out below and allow us a reasonable period to remediate
  • We treat your report confidentially and pass it on to third parties only where this is necessary for remediation or required by law (for example reports to CSIRTs/ENISA, or coordination with suppliers)

We currently do not operate a bug bounty programme; reports are not remunerated.

3. Rules for security researchers

Please observe the following principles during your research:

Welcome

  • Testing exclusively on systems and devices that you own or for which you have explicit permission
  • Demonstrating the vulnerability with the minimum intrusion necessary
  • Treating your findings as confidential until an advisory is published, or for a maximum of 90 days from our acknowledgement of receipt

 

Not permitted

  • Accessing, modifying or exfiltrating data belonging to others
  • Impairing availability (DoS/DDoS, load testing, brute forcing)
  • Testing on machines in customer operation or on third-party production systems
  • Social engineering or phishing directed at our employees, suppliers or customers
  • Physical attacks against sites or individuals
  • Publishing details before coordinating with us

4. Scope

In scope

  • Our products incorporating digital elements, in particular machine control systems, HMI/operating software, communication interfaces, and the accompanying and analysis software developed by us.
  • Software developed and supplied by us
  • Services operated by us
  • Our publicly accessible infrastructure: https://www.klotz.de/ and subdomains

 

Out of scope

  • Third-party systems and services, even if we use them (e.g. RMS, SCADA, …). Please report vulnerabilities in third-party systems directly to the relevant provider.
  • Machines that have been modified by the operator or are operated outside the documented conditions of use
  • Findings with no verifiable security impact, e.g. missing best-practice headers, SPF/DMARC warnings without a specific attack vector, self-XSS, results from scanner runs alone without verification, AI-generated findings without verification
  • Vulnerabilities in software after the end of the support period (see Section 7) are not covered by these commitments; however, we would still welcome reports of such vulnerabilities.

5. How we handle your report

Reports are processed by our Product Security Incident Response Team (PSIRT) following a defined process:

  1. Receipt and acknowledgement – logging of the report, assignment of a case number
  2. Triage – verification, identification of affected products and versions
  3. Assessment – risk rating in accordance with CVSS v4.0, supplemented by the machine and operating context
  4. Remediation – development, testing and release of a fix or an interim measure (workaround)
  5. Publication – security advisory and provision of the security update
  6. Follow-up – root cause analysis and feedback of the findings into our development process

 

Where a public identifier (CVE) is appropriate for a vulnerability, we arrange for it to be assigned through the responsible body. Actively exploited vulnerabilities and severe security incidents are reported to the competent authorities within the statutory deadlines.

6. Security advisories

We publish remediated vulnerabilities in our products together with the corresponding security update:

  • Overview of all advisories: www.klotz.de/security-advisories
  • Notification: operators of our machines are additionally informed directly through the contacts on file. To be added to the distribution list, write to security[at]klotz[dot]de.

 

An advisory contains as a minimum: affected products and versions, a description of the vulnerability, its impact, its severity, the available fix and, where applicable, interim measures.

For customers with automated vulnerability management, we are evaluating additional provision in machine-readable form. Please contact us if you have a requirement.

Please notify us of any changes to your contacts so that security information reaches the right people.

7. Product and update security

Provision of updates: We provide security updates. For machines without a network connection, updates are supplied as a signed offline package with a checksum and installation instructions.

Integrity: All update packages are digitally signed. We publish checksums and signatures together with the package. Please verify them before installation.

Software bill of materials (SBOM): We maintain a software bill of materials for our products in CycloneDX format. Customers can obtain the SBOM on request via security[at]klotz[dot]de or through their sales contact.

Secure operation: Guidance on secure commissioning and hardening of our machines (network segmentation, access, remote maintenance, password changes) is provided in the respective operating manual. Securing the operating environment is the responsibility of the operator.

Support period: For each of our products containing digital elements, we guarantee a support period of at least five years from the date of release. During this period, we will effectively address vulnerabilities and provide security updates free of charge. For many of our systems, a longer support period applies in line with their expected service life; you will find the specific period applicable to your product in the relevant product documentation. You can obtain information about your system’s support period at any time by contacting security[at]klotz[dot]de. Once the support period has expired, we will continue to accept reports but can no longer guarantee that a fix will be provided.

8. Regulatory framework

Cyber Resilience Act (Regulation (EU) 2024/2847). We manufacture custom-engineered machinery including the control and operating software running on it, and are therefore a manufacturer of products with digital elements within the meaning of the CRA. The coordinated vulnerability disclosure policy described on this page and the single point of contact for vulnerability reports form part of our obligations under the CRA and are additionally set out in the product documentation. Actively exploited vulnerabilities and severe security incidents are reported in accordance with the deadlines of the CRA (early warning within 24 hours, notification within 72 hours, final report within 14 days or one month respectively).

NIS2 / BSIG. NIS2 / BSIG. As a company we operate an information security management system whose measures are based on ISO/IEC 27001. These include risk management, incident handling, business continuity and recovery planning, access control with multi-factor authentication, cryptography and the security of our supply chain.

9. Security incidents affecting customers

Where a security incident within our company may affect our customers, their machines or their data, we actively inform the affected customers through the contacts on file and, where necessary, via this page.

If you wish to report an incident affecting us as a company – for instance misuse of our name, fraudulent invoices or compromised accounts – please also use security[at]klotz[dot]de.

10. Requirements for our suppliers

Security does not stop at the factory gate. From suppliers of software, components and IT services we expect:

  • a named security contact and a documented vulnerability handling process
  • prompt notification of vulnerabilities and incidents affecting our products or our operations
  • a software bill of materials (SBOM) for supplied software components
  • security updates throughout the agreed product lifecycle

 

The details are governed by contract. Questions are answered by security[at]klotz[dot]de.

11. Data protection for reports

In order to process your report we handle the data you submit, in particular contact details and technical information. The legal basis is Art. 6(1)(c) and (f) GDPR in conjunction with our statutory obligations regarding vulnerability handling. We retain the data for the period specified by law for record-keeping purposes. It is disclosed only where this is necessary for remediation or required by law. Further information at Privacy policy.