Coordinated Vulnerability Disclosure Policy

Scope

This policy applies to security vulnerabilities in products and services of NewTec GmbH. It describes how to report a vulnerability to us, what you can expect from us, and how we handle disclosure together with you.

It does not apply to attacks against NewTec's own IT systems. A different team is responsible for those. Please report such a case through the channels described in this policy anyway, and we will route it internally.

How to report

Write to security@newtec.de or use the form at https://www.newtec.de/en/security.

If you want to report confidentially, please encrypt your message with our public key, available at https://www.newtec.de/security/openpgp-key_psirt.asc.

You may report anonymously. In that case, however, we cannot reply to you.

What we commit to

  • We acknowledge receipt of your report: within 5 working days
  • We reply with our findings on which products are affected: within 10 working days
  • We keep you informed about progress: at reasonable intervals
  • We publish a security advisory: usually within 90 days of your report

Acknowledgement is given by a person. We do not consider an automated reply alone to satisfy this commitment.

These periods start when your report reaches us. Working days are Monday to Friday, excluding public holidays at the location of the handling team.

Disclosure

We aim for coordinated disclosure. The normal case is publication within 90 days of receiving your report.

If remediation needs more time, for instance because a supplier component is affected or because a field update has to be coordinated, we will agree an extension with you and explain why. We will not stall you without giving reasons.

If a vulnerability is demonstrably already being exploited, we may publish earlier, because protecting users then takes precedence. We will tell you if that happens.

On request we will credit you by name in the advisory. We do so only with your explicit consent.

What we ask of you

  • Give us enough information to reproduce the behaviour.
  • Give us the opportunity to fix the vulnerability before you publish it.
  • Do not access third-party data, and do not modify or delete any data.
  • Do not impair the availability of our systems or those of our customers. In particular, refrain from denial-of-service testing.
  • Do not use attacks aimed at people, meaning no impersonation and no attempts to obtain employee credentials.
  • Only test on devices and installations you are authorised to test. A device in service at a customer site is not one of them.

Our commitment to you

If you follow the points above and report a vulnerability to us in good faith, we will not take legal action against you and will not file a criminal complaint. We regard your report as a contribution to the security of our products.

We do not require you to sign a non-disclosure agreement as a precondition for receiving or handling your report.

This commitment cannot prevent us from complying with legal obligations, and it does not extend to conduct going beyond finding and reporting a vulnerability.

What this policy is not

This policy is not a bug bounty programme. We do not pay rewards for reported vulnerabilities.

It does not create a right to any particular handling of your report, nor a right to publication.

Contact and languages

We accept reports in German and in English and reply in the same language.

NewTec GmbH, security@newtec.de