Safety at SCHMACHTL
Vulnerability Reports
)
)
The security of our products, software solutions, digital services, and IT systems is a top priority for SCHMACHTL. Despite careful development, testing, and continuous improvements, security vulnerabilities cannot be completely ruled out.
We welcome reports from our customers, partners, and others who responsibly report potential vulnerabilities. Through coordinated disclosure of security vulnerabilities, we work together to continuously improve the security of our products and that of our customers.
Scope
This policy applies to vulnerability reports regarding products with digital elements, as well as digital solutions and services, to the extent that these are developed, manufactured, provided, operated, or managed by SCHMACHTL and have a direct or indirect logical or physical data connection to a device or network.
This includes, in particular:
- Digital services, customer portals, and cloud solutions provided by SCHMACHTL;
- Software, apps, firmware, and other digital product components from SCHMACHTL;
- Products with digital elements for which SCHMACHTL acts as the manufacturer, provider, importer, or other responsible party;
- Connected devices, systems, components, and control systems whose intended or reasonably foreseeable use includes a data connection to other devices or networks.
If the report concerns a third-party product obtained through SCHMACHTL, we will determine our jurisdiction and, if necessary, coordinate further handling with the respective manufacturer or provider.
Excluded from the Scope of Application
This policy does not apply to:
- Products, systems, and components that are not developed, manufactured, operated, or managed by SCHMACHTL;
- Third-party products, provided that SCHMACHTL is neither the manufacturer nor the responsible entity;
- Products and areas that are exempt from Directive 2024/2847 due to legal or regulatory requirements, in particular certain medical devices, in vitro diagnostic medical devices, vehicle systems, aviation products, marine equipment, and products developed exclusively for national security, defense, or the processing of classified information;
- Products and systems subject to equivalent or overriding sector-specific cybersecurity requirements;
- Replacement parts intended exclusively for the replacement of identical components and manufactured to the same specifications;
- Reports based on security tests in which data was altered, manipulated, deleted, or stolen;
- Reports resulting from tests that have affected or could have affected the availability of systems or services.
In particular, the following are excluded from the scope of application
The following systems, areas, and practices are expressly excluded from the scope of this policy:
- Any network infrastructure of SCHMACHTL GmbH (e.g., routers, switches, firewalls, and other network components);
- Systems and services not expressly covered by the scope of this policy;
- Social engineering;
- Phishing or similar attempts at deception;
- Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) attacks;
- The use of exploits, scripts, or other tools that go beyond the necessary demonstration of a vulnerability;
- Security tests that go beyond a proof of concept (PoC);
- The use of systems or attack methods not expressly covered by this policy.
Principles for Security Testing
All reported security vulnerabilities are carefully reviewed and assessed by Schmachtl. The following guidelines must be observed during security testing:
- Act exclusively in good faith and within the described scope.
- Test vulnerabilities only to the extent absolutely necessary. Exploitation must not go beyond a minimal proof of concept.
- Cease further testing activities immediately once the vulnerability has been demonstrated.
- Do not alter, delete, manipulate, copy, publish, or exfiltrate any data.
- Do not compromise the availability, integrity, or confidentiality of systems, services, or data.
- Do not conduct tests that could lead to service interruptions, performance degradation, or security risks for third parties.
- Do not use or distribute exploit tools, scripts, or information that could enable malicious exploitation by third parties. Proof-of-concept information may only be transmitted to Schmachtl on a confidential basis.
- Do not use vulnerabilities for unauthorized access, financial gain, extortion, reputational damage, or any other unlawful purposes.
Handling Unintended Consequences
Should security testing inadvertently result in a violation of these guidelines, access to data, disruption of systems, or any other undesirable effect, please contact us immediately. This will allow us to jointly assess any potential consequences and take appropriate measures to mitigate the damage.
Legal Assurance for Responsible Reporting
SCHMACHTL does not intend to assert civil claims or initiate criminal proceedings provided that the reporter acts in good faith, complies with this policy, tests exclusively within the defined scope, and reports the vulnerability to SCHMACHTL confidentially.
This assurance does not apply in cases of malicious conduct, unauthorized data processing, data alteration, data leakage, extortion, disclosure of sensitive information, attacks on system availability, intentional damage, or other unlawful acts. The legal powers of public authorities remain unaffected.
No Compensation
This program is not a bug bounty program. There is no entitlement to compensation, rewards, reimbursement of expenses, or any other form of consideration for a report.

Confidentiality and Coordinated Disclosure
We ask reporters not to publicly disclose information about potential security vulnerabilities before SCHMACHTL has reviewed the report, implemented appropriate measures, or agreed with the reporter on an appropriate time for disclosure.
SCHMACHTL strives to ensure coordinated disclosure within a reasonable timeframe. In complex cases, a longer coordination period may be necessary. If necessary, a competent coordinating body or government agency may be involved.
Processing and Feedback
Once we receive your report, we will review the information you provided. Our Product Security Team will assess the relevance, reproducibility, and impact of the vulnerability. If necessary, we will contact you with any questions.
Within 5 business days, you will receive an acknowledgment of receipt for your report. To receive this, you must provide a valid email address.
Within the next ten business days, you will receive an interim report from us. If the review takes longer, we will specify a firm follow-up date in this message, at which time we will contact you again without further notice.
After confirming the vulnerability, we assess its risk potential based on the following factors: the potential harm to our customers and the likelihood of exploitation. Based on this assessment, we classify the vulnerability according to its priority for resolution.
The process is considered complete once one of the following conditions is met:
- The investigation shows that no security vulnerability exists.
- The security vulnerability has been fully resolved through technical measures.
- Affected customers have been directly informed of the risk.
- An official security advisory has been published.
If a report concerns a security incident, a data breach, or a legal reporting requirement, it is forwarded internally to the relevant department responsible for IT security, data protection, and compliance.
Official Reporting Channel
If a security vulnerability or suspected security vulnerability is discovered in a SCHMACHTL product, software solution, digital service, or application provided by SCHMACHTL, please report it to us using the form below or via email.
Notice Regarding Data Protection.
The personal data submitted as part of a vulnerability report is processed for the purposes of receiving, reviewing, handling, documenting, and tracking the report. The legal basis for this processing is, in particular, our legitimate interest in IT, product, and information security, as well as, where applicable, compliance with legal obligations.
Access to the report is granted only to those internal departments and external service providers, manufacturers, government agencies, or coordinating bodies that are necessary for processing, legal assessment, or legally required reporting. For more information, please see our Privacy Policy: Schmachtl GmbH Privacy Policy

)
)
)
)