Philosophy on Coordinated Disclosure
Lapmaster Wolters GmbH believes that effective coordinated disclosure of vulnerabilities requires mutual trust, respect, and transparency between Lapmaster Wolters GmbH and reporters. Together, through our expertise and vigilance, we help ensure the long-term security and data protection of Lapmaster Wolters GmbH’s customers, products, and services.
We are guided by the principle of Coordinated Vulnerability Disclosure (CVD): A reported vulnerability should be assessed, addressed, and—if disclosed publicly—disclosed in a coordinated manner.
Scope
All hardware products and their software, as well as the corresponding configuration programs, that belong to the Lapmaster Wolters brand.
Reporting a vulnerability
Please report suspected vulnerabilities using the form below.
Please provide the following information if possible:
- Affected product and version
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Proof of concept, screenshots, or log files (if available)
- Your contact details for follow-up questions
Reports may be submitted in German or English. Receipt of a vulnerability report will be acknowledged within three business days. We will maintain contact with the reporter throughout the CVD process as necessary for handling the report.
We ask security researchers and reporters to act responsibly.
In particular, we expect that:
production facilities, machinery, or customer environments are not disrupted,
third-party systems or data are not manipulated, compromised, or altered, and no data is unnecessarily accessed or exfiltrated,
no denial-of-service, social engineering, spam, brute-force, or similar attacks are conducted,
the vulnerability is not exploited maliciously and testing is limited to the extent necessary to demonstrate the issue,
results from automated tools or scans are reported only with clear technical documentation,
details regarding the vulnerability are kept confidential until an agreed-upon publication date.
This policy does not grant permission for actions that violate applicable laws, contractual obligations, or property rights.
Provided that reporters comply with this policy, cause no damage, do not compromise the privacy or security of third parties, and commit no criminal acts, Lapmaster Wolters GmbH will not pursue legal claims against the reporting individual in connection with the proper reporting of a vulnerability.
Upon receipt of a report, we will:
acknowledge receipt of the report within three business days,
assess and validate the report,
ask follow-up questions if necessary,
develop and coordinate appropriate patches or mitigation measures, taking into account any agreed-upon publication date,
inform affected stakeholders if required,
disclose the vulnerability as part of a coordinated disclosure process and, if necessary, issue a security advisory detailing the affected products or versions and available patches or mitigation measures.
We commit to,
carefully reviewing every report,
treating reporters respectfully and professionally,
prioritizing vulnerabilities based on risk,
striving for coordinated disclosure,
treating every vulnerability report confidentially within the scope of applicable law,
not sharing the reporter's personal data with third parties without their express consent,
providing feedback on every vulnerability report and remaining available as a point of contact throughout the process.