Vulnerability Disclosure Policy (VDP)

1. Purpose

At ATRON, the security of our products and services is an important priority. We appreciate responsible security research and encourage researchers, customers and partners to report potential security vulnerabilities. This Vulnerability Disclosure Policy describes how to report vulnerabilities and how we handle reported issues.

2. Scope

This policy applies to:

  • Embedded products
  • Backend services
  • Cloud services
  • Web applications
  • Mobile applications
  • APIs
  • Other software developed and maintained by ATRON electronic GmbH

Out-of-scope systems may be identified separately where applicable. Third-party products or services not developed or operated by ATRON are out of scope unless explicitly stated otherwise.

3. Reporting a Vulnerability
Please send vulnerability reports to: psirt@atron.com. Please do not report security vulnerabilities through customer support channels or social media. Encrypted reports may be submitted using S/MIME or OpenPGP. Our OpenPGP public key is available at: https://www.atron.com/security/pgp. Please use the email subject “Security Vulnerability Report”. Please include whenever possible:

  • affected product or service
  • product version
  • affected component
  • vulnerability description
  • steps to reproduce
  • proof of concept (if available)
  • potential impact
  • CVE reference (if already assigned)
  • your contact information
  • configuration required
  • screenshots or log files (if applicable)
  • attack prerequisites (if known)

4. What We Expect

We ask researchers to:

  • Act in good faith and in accordance with this Vulnerability Disclosure Policy
  • Respect the privacy of our customers, users and employees.
  • Avoid accessing, modifying or retaining customer or personal data beyond what is reasonably necessary to demonstrate the vulnerability.
  • Do not disrupt production systems or intentionally degrading service availability beyond what is reasonably necessary to demonstrate the vulnerability.
  • Do not perform denial-of-service (DoS) attacks or deploy malware.
  • Do not conduct physical attacks or use social engineering techniques.
  • Do not exploit a vulnerability beyond what is reasonably necessary to demonstrate its existence.
    Report vulnerabilities confidentially and refrain from public disclosure until ATRON has had a reasonable opportunity to investigate and address the issue.
  • If you inadvertently access confidential or personal information during your research, do not retain, modify or share it beyond what is reasonably necessary to demonstrate the vulnerability.
  • Report the issue promptly and securely
  • Delete any such information after submitting your report

5. Safe Harbor

We appreciate your efforts to improve the security of our products and services.
Provided you act in accordance with this policy, we will consider your research authorized.
We will not initiate legal action against researchers who:

  • act in good faith
  • avoid unnecessary damage
  • respect this policy
  • report findings responsibly

We ask that you promptly delete any confidential information obtained during your research after reporting the vulnerability.

6. Our Commitment

After receiving a report we aim to:

  • Acknowledge receipt usually within 5 business days
  • Initial assessment

We will perform an initial assessment and keep you informed about the progress of the investigation.
We perform an initial triage including

  • reproducibility of the reported vulnerability
  • exploitability assessment
  • severity assessment
  • affected components
  • exploitability
  • customer impact

Ongoing communication
We will keep the reporter informed about the progress whenever possible.

Remediation
Confirmed vulnerabilities are evaluated according to our internal Product Security Incident Response Process (PSIRT). Depending on the nature and severity of the reported vulnerability, we may

  • publish a security advisory
  • provide software updates
  • publish mitigations
  • assign a CVE where appropriate

7. Coordinated Vulnerability Disclosure

ATRON supports the principles of Coordinated Vulnerability Disclosure (CVD). We kindly ask researchers not to publicly disclose vulnerabilities until:

  • affected customers have been informed, where appropriate.
  • a remediation or mitigation is available, where reasonably possible.
  • a mutually agreed disclosure timeline has been reached.

We generally aim for coordinated public disclosure after remediation or mitigation has been made available or an agreed disclosure timeline has been reached.

8. Product Security Incident Response Team (PSIRT)

ATRON’s Product Security Incident Response Team (PSIRT) is responsible for:

  • receiving and tracking vulnerability reports
  • performing vulnerability triage
  • assessing security risks and product impact
  • coordinating with product development teams
  • tracking remediation activities
  • coordinating regulatory reporting, where required
  • communicating with customers and security researchers
  • coordinating vulnerability disclosure

9. Severity Assessment

Reported vulnerabilities are evaluated using established industry standards, practices and, where appropriate, recognized methodologies, including:

  • CVSS
  • EPSS (where appropriate)
  • exploit maturity
  • customer exposure
  • business impact

The prioritization of remediation activities is based on the technical severity, exploitability, product impact and potential customer risk, in accordance with ATRON's Vulnerability Management Process.

10. Personal Data

Please submit only the information necessary to describe and reproduce the reported vulnerability. Any personal data provided as part of a vulnerability report will be processed solely for the purpose of receiving, assessing and handling the reported vulnerability. Personal data will be processed in accordance with our Privacy Policy, available at: Data Protection - ATRON Group

11. Contact

Product Security Incident Response Team (PSIRT)
Email: psirt@atron.com
Website: https://atron.com/security
We prefer vulnerability reports to be submitted in English. Reports submitted in German are also accepted.