Coordinated Vulnerability Disclosure Policy

Version 1.0 · Last updated: 25 September 2026

Security vulnerabilities cannot be avoided entirely. What matters is how they are handled. This policy explains how to report a vulnerability to us, what you can expect from us, and what we expect from you. It takes effect on the date of publication and is reviewed at least once a year.

01 Products covered by this policy

VIDEOR distributes security technology from a wide range of brands. Whether we manufacture a product or distribute it affects the commitments we can make. That distinction is set out here.

Our own brands – eneo, SOLVIDO and jetrics

We are the manufacturer of these products. We receive and assess your report, remedy the vulnerability, provide a security update, and disclose the vulnerability in accordance with Section 8. All commitments in this policy apply in full.

Products from other manufacturers

For these products, we are a distributor or importer, not the manufacturer. We take your report just as seriously and promptly forward it to the manufacturer's reporting contact. We tell you to whom we have forwarded it and remain your point of contact at VIDEOR. However, the manufacturer decides how the vulnerability is remedied and when it is disclosed. We cannot commit to a deadline for those steps. You may also contact the manufacturer directly.

Our own services

This policy also applies to the online services and portals we operate, as well as cloud and remote access services that form part of the functionality of our products.

02 What we consider a vulnerability

We handle a report as a vulnerability report under this policy if it meets the following criteria:

  • It concerns a product we distribute or infrastructure we operate.
  • It describes an issue that is not yet publicly known.
  • It contains more than the output of an automated tool. We cannot process scanner results without supporting evidence that allows us to understand the issue.

We also review reports that do not meet these criteria, such as information about vulnerabilities that have already been fixed. We acknowledge receipt and explain why we will not continue handling the report as a coordinated vulnerability disclosure case.

03 How to contact us

Reporting form
videor.com/sicherheit/schwachstelle-melden – anonymous reports are also possible
Product PSIRT
[email protected] · responsible for vulnerabilities in our products and services
Telephone
+49 6074 888-0
Post
VIDEOR E. Hartig GmbH, Attn: Produktsicherheit, Carl-Zeiss-Straße 8, 63322 Rödermark, Germany
Languages
German and English

We accept email addresses and telephone numbers as contact methods. For confidential information, we strongly recommend using encrypted and digitally signed email. We can also reply in encrypted form on request; please provide your public key for this purpose.

Anonymous reporting

You can report anonymously, most easily through the reporting form. We accept and process anonymous reports.

Please bear in mind: If you report anonymously without providing a way to contact you, we cannot ask follow-up questions. Complex issues often require clarification or additional material. We may therefore be able to process an anonymous report only to a limited extent, or not at all. If you want to remain reachable without giving your name, an anonymous email address is sufficient. Our ability to process a report may also be limited if you do not respond to follow-up questions.

You may also report a vulnerability indirectly and, if you wish, anonymously through a CSIRT designated as a coordinator for coordinated vulnerability disclosure under Article 12(1) of Directive (EU) 2022/2555. In Germany, this is CERT-Bund at the Federal Office for Information Security (BSI). In such cases, we work with the CSIRT without requiring you to identify yourself to us.

04 What you can expect from us

Initial response

Within five business days – from a person, not an automated system.

Substantive response

Within ten business days.

Status updates

At least every 30 days thereafter until the case is closed.

Anonymous reports

If no contact method is provided, we cannot respond and these deadlines do not apply.

Our substantive response will include at least one of the following: our assessment of whether we confirm or reject the vulnerability; specific questions we need answered to understand it; or an explanation of why the assessment is taking longer, together with a commitment to contact you again within a further ten business days.

You are welcome to ask about the status of your report. Simply contact us and include your case number.

05 Our commitments

  • Confidentiality. We treat your report confidentially to the extent permitted by law. This does not include information required for disclosure under Section 8.
  • No sharing of your personal data without your consent. We do not share your personal data with third parties, including the manufacturer of an affected third-party product, unless you expressly consent. We may forward the report itself without your contact details.
  • No legal action. As long as you comply with this policy and its principles, we will not initiate legal action against you or file a criminal complaint. This commitment does not apply where criminal intent is evident.
  • No non-disclosure agreement. We do not require you to sign a non-disclosure agreement.
  • One point of contact throughout the process. We remain available for a constructive and confidential exchange throughout the case.
  • Review by two people. No report is finally assessed and closed by one person acting alone.
  • Respect. We treat one another respectfully. Discrimination, insults and demeaning behaviour have no place on either side.

06 What we expect from you

To help us handle your report in an orderly way, please:

  • Do not exploit the vulnerability beyond what is necessary to demonstrate it. Do not cause harm.
  • Do not attack our systems or infrastructure, including through social engineering, spam, denial-of-service attacks or brute-force attacks.
  • Do not alter, compromise or delete systems or data belonging to third parties.
  • Do not access or copy other people's data. If you encounter such data unavoidably, stop and inform us.
  • Do not share the vulnerability with third parties or publish it before the agreed time.
  • Describe the issue in enough detail for us to understand it, ideally including steps to reproduce it.
  • If possible, provide a way to contact you, preferably an email address.

If you do not follow these points, we will still make every reasonable effort to process your report; product security remains our priority. However, our commitment in Section 5 not to take legal action cannot apply in that case.

07 How we handle a report

  1. Receipt. We record your report with a timestamp and assign a case number.
  2. Initial response within five business days.
  3. Assessment. We reproduce the issue, identify affected products and versions, and assess its severity. We ask follow-up questions if needed.
  4. Substantive response within ten business days.
  5. Remediation. For our own brands, we develop and distribute a security update or another mitigation. For third-party products, we follow up with the manufacturer.
  6. Disclosure under Section 8, in coordination with you.
  7. Closure under Section 10.

08 Disclosure

We disclose confirmed and verified vulnerabilities in our own brands within 90 days of receiving your report. The key consideration is that users must be able to protect themselves. We therefore generally disclose a vulnerability as soon as a security update or mitigation is available.

If the vulnerability cannot be remedied within that period for a justifiable reason, the deadline may be extended once by a further 90 days. We coordinate this closely with CERT-Bund. Only CERT-Bund can grant any further extension at our request.

We disclose vulnerabilities at least through the European Vulnerability Database (EUVD) maintained by ENISA, and additionally through our security advisories at videor.com/sicherheit.

We coordinate the timing with you. If you have your own disclosure schedule, please tell us early. Earlier disclosure may be necessary if a vulnerability is already being actively exploited.

If a vulnerability is identified and remedied before the affected product is placed on the market, disclosure is not required.

09 Actively exploited vulnerabilities

If there is credible evidence that a vulnerability in one of our products or in our infrastructure is being actively exploited, we promptly notify CERT-Bund at the Federal Office for Information Security (BSI), the coordinating CSIRT designated for Germany, as well as ENISA. We keep CERT-Bund informed of new findings, mitigations and their planned timing, and coordinate these steps with CERT-Bund.

If you have evidence of active exploitation, please tell us explicitly. This is the information most likely to accelerate the process. You may also contact CERT-Bund directly.

10 When a case is closed

We consider a case closed when one of the following applies:

  • Our assessment finds that the reported issue is unfounded.
  • A vulnerability in a service we operate has been remedied and disclosed.
  • A vulnerability in a product has been remedied, a security update is available, and the vulnerability has been disclosed.
  • For a third-party product, the manufacturer has closed the case or informed us that it will not pursue it further.
  • We cannot continue processing the report because necessary follow-up questions remain unanswered.

We inform you promptly when the case is closed, unless you reported anonymously without a contact method.

11 Changes to this policy

We review this policy at least once a year and update it as needed. The version published on our website is authoritative; the date of the last update appears at the beginning of this document. An ongoing case is governed by the version published when we received the report.