1. Purpose
At ATRON, the security of our products and services is an important priority. We appreciate responsible security research and encourage researchers, customers and partners to report potential security vulnerabilities. This Vulnerability Disclosure Policy describes how to report vulnerabilities and how we handle reported issues.
2. Scope
This policy applies to:
Out-of-scope systems may be identified separately where applicable. Third-party products or services not developed or operated by ATRON are out of scope unless explicitly stated otherwise.
3. Reporting a Vulnerability
Please send vulnerability reports to: psirt@atron.com. Please do not report security vulnerabilities through customer support channels or social media. Encrypted reports may be submitted using S/MIME or OpenPGP. Our OpenPGP public key is available at: https://www.atron.com/security/pgp. Please use the email subject “Security Vulnerability Report”. Please include whenever possible:
4. What We Expect
We ask researchers to:
5. Safe Harbor
We appreciate your efforts to improve the security of our products and services.
Provided you act in accordance with this policy, we will consider your research authorized.
We will not initiate legal action against researchers who:
We ask that you promptly delete any confidential information obtained during your research after reporting the vulnerability.
6. Our Commitment
After receiving a report we aim to:
We will perform an initial assessment and keep you informed about the progress of the investigation.
We perform an initial triage including
Ongoing communication
We will keep the reporter informed about the progress whenever possible.
Remediation
Confirmed vulnerabilities are evaluated according to our internal Product Security Incident Response Process (PSIRT). Depending on the nature and severity of the reported vulnerability, we may
7. Coordinated Vulnerability Disclosure
ATRON supports the principles of Coordinated Vulnerability Disclosure (CVD). We kindly ask researchers not to publicly disclose vulnerabilities until:
We generally aim for coordinated public disclosure after remediation or mitigation has been made available or an agreed disclosure timeline has been reached.
8. Product Security Incident Response Team (PSIRT)
ATRON’s Product Security Incident Response Team (PSIRT) is responsible for:
9. Severity Assessment
Reported vulnerabilities are evaluated using established industry standards, practices and, where appropriate, recognized methodologies, including:
The prioritization of remediation activities is based on the technical severity, exploitability, product impact and potential customer risk, in accordance with ATRON's Vulnerability Management Process.
10. Personal Data
Please submit only the information necessary to describe and reproduce the reported vulnerability. Any personal data provided as part of a vulnerability report will be processed solely for the purpose of receiving, assessing and handling the reported vulnerability. Personal data will be processed in accordance with our Privacy Policy, available at: Data Protection - ATRON Group
11. Contact
Product Security Incident Response Team (PSIRT)
Email: psirt@atron.com
Website: https://atron.com/security
We prefer vulnerability reports to be submitted in English. Reports submitted in German are also accepted.