Digital Products Vulnerabilities
Report a Digital Product Vulnerability
At WITTKOPP, we are committed to continuously improving the security of our products and digital solutions. As our portfolio evolves to include connected and digitally enabled solutions, safeguarding our customers against cybersecurity risks is a top priority. Security researchers, customers, and suppliers may report potential vulnerabilities in our products.
This page outlines how to report a vulnerability and what to expect from us throughout the process.
For vulnerabilities affecting Gunnebo’s IT estate, gunnebo.com, or other Internet facing services accessible via the , please refer to Gunnebo’s “Coordinated Vulnerability Disclosure (CVD)” page and follow the reporting process described there.
Scope and Responsible Disclosure
This process applies primarily to products with digital components, as well as to digital solutions supported and maintained by WITTKOPP.
Submission of a report does not create any contractual relationship, entitlement to compensation, or obligation on our part to implement a specific remediation measure or disclosure approach. We will not pursue legal action solely on the basis of good-faith security research conducted in accordance with these guidelines and applicable law
we will not pursue legal action solely on the basis of good-faith security research conducted in accordance with these guidelines and applicable law.
Select the appropriate reporting channel
How to Report a Vulnerability
This reporting channel is intended for reporting vulnerabilities affecting products with digital elements and related product security concerns. If you believe you have discovered a security vulnerability in those products, please use the appropriate form below to report potential product security vulnerabilities based on your role.
Supplier report
Report a potential vulnerability in a product, component, service, or technology supplied to WITTKOPP.
Customer or researcher report
Report a potential vulnerability in a WITTKOPP product or related digital service as a customer,researcher, partner, or other external party.
Responsible Disclosure Guidelines
We kindly ask that reporters:
Investigation Period
Allow us a reasonable period to investigate and remediate the issue before any public disclosure.
Responsible Testing
Avoid exploiting the vulnerability beyond what is necessary to demonstrate it.
Privacy Policy
Do not access other people's data, and do not modify or delete data that does not belong to you.
Direct Report
Please contact us directly using the contact form provided.
Process Flow
What Happens After you submit a report
We follow coordinated vulnerability disclosure principles. The exact process and timing may vary depending on the nature and complexity of the issue, but it will normally include the following stages:
01
Submission received
We aim to acknowledge receipt of vulnerability reports within a reasonable timeframe.
02
Initial assessment
We review the information and may request further details. Where required, we comply with applicable regulatory reporting obligations
03
Investigation and action
We investigate the issue and determine the appropriate remediation or mitigation.
04
Coordinated Communication
Where relevant, we coordinate remediation and disclosure with the reporter.
Contact
General product security enquiries
For enquiries that are not related to a digital product vulnerability report, please use the general contact page.