Confidential product vulnerability disclosure guidelines for VIVAVIS products

1. Purpose and Scope

VIVAVIS AG accepts reports regarding potential vulnerabilities in its software, firmware, and hardware products, as well as in the associated components, applications, and interfaces for which it is responsible.

These guidelines describe:

  • how vulnerabilities can be reported to VIVAVIS securely
  • which information is helpful for an evaluation,
  • how VIVAVIS handles vulnerabilities disclosed to it,
  • and which principles apply to the investigation and any coordinated publication.

The guidelines do not apply to:

  • general support inquiries,
  • feature requests,
  • standard product defects unrelated to security,
  • or security issues in third-party products for which VIVAVIS is neither the manufacturer nor the product provider.

Please send such requests to support@vivavis.com.

2. Notification address

Potential vulnerabilities can be reported to the following address:

vulnerability@vivavis.com

For sensitive technical information, the email can be encrypted using an S/MIME certificate. You can download the certificate here: <URL to certificate vulnerability@vivavis.com_base64.cer>

Please use a descriptive subject line if possible, for example:

„Confidential Vulnerability Report – [Product name] – [Version]“

3. Content of report

Please provide the following information, if possible:

  • a brief summary in a few words
  • Product name and full version details
    We require the exact product name (e.g., from the product manual) and the full version number of the software you are using.
  • affected components
    Complex products will typically consist of several component parts. If known, and to the extent possible, please specify the part affected by the vulnerability.
  • Description of findings
    A detailed description of the vulnerability
  • reproducible steps for reproduction
    Please explain which tools or methods can be used to uncover the vulnerability (include screenshots or other illustrations if applicable).
  • System and environment information
    Please describe the operating environment of the software or device in as much detail as possible.
  • Potential impacts
    Here, we would like to ask you to describe the impact of the exploitation or to provide an assessment of the damage an attacker could cause—or has already caused.
  • CVE, CWE, or CVSS information, if known and / or already exstant
  • as well as a way to contact for further questions

We will review the report promptly and get back to you. The more complete and clear the information provided, the better VIVAVIS can assess your report. A vulnerability report will not be rejected simply because some of this information is missing.

Purely machine-generated reports —for example, from a scan—that lack an explanation of the specific finding, the affected product, and the potential impact can, as a rule, not be conclusively evaluated. In such cases, VIVAVIS may reach out to request supplementary information.

4. Handling incoming reports

VIVAVIS will:

  • acknowledge receipt of a report, provided a means of contact has been specified;
  • check the report for plausibility and relevance;
  • request additional information if necessary;
  • investigate the potential impact on products and versions;
  • evaluate necessary remedial actions or measures to mitigate the risk;
  • and inform the reporting person of significant changes in status, insofar as possible and appropriate.

If a vulnerability is confirmed, VIVAVIS determines appropriate measures based on a risk assessment. These may include, in particular, security updates, configuration guidelines, workarounds, or security advisories.

The nature and scope of communication depend, among other things, on criticality, exploitability, product impact, the availability of a remedial measure, and the legitimate interests of affected customers and third parties.

5. Confidentiality and Data Protection

VIVAVIS treats vulnerability reports and the information contained therein as strictly confidential and limits access to the individuals and units responsible for verification, assessment, remediation, legal evaluation, or necessary communication.

Personal data is processed only to the extent necessary for processing the report, communicating with the reporting person, fulfilling legal obligations, or safeguarding legitimate interests.

A transmission may, in particular, be necessary to:

  • affected companies in the VIVAVIS-Group,
  • manufacturers of affected products and component parts,
  • commissioned technical service providers,
  • CERTs or CSIRTs,
  • competent authorities,
  • Legal or security advisors,
  • or affected customers.

In each case, only the information necessary will be disclosed. To the extent possible, the identity of the reporting person and any personal data will not be disclosed.

Further information can be found in the privacy policy:

https://www.vivavis.com/en/service/data-privacy/

6. Principles for safety inspections

VIVAVIS welcomes good-faith white-hat security research aimed at responsibly identifying vulnerabilities and reporting them to VIVAVIS on a confidential basis.

Please pay particular attention to the following principles:

  • Limit inspections to the extent necessary to identify and transparently document a potential security issue.
  • Avoid damage, business interruptions, and impairments to availability.
  • Do not access data unless strictly necessary to confirm the finding.
  • Do not modify, delete, copy, or publish third-party data.
  • Do not use any access capabilities you have obtained for other purposes.
  • Do not conduct social engineering, phishing, spam, denial-of-service, distributed denial-of-service, or uncontrolled brute-force attacks.
  • Do not test third-party systems or infrastructure without authorization.
  • Do not install malware or set up persistent access.
  • Do not sell or distribute exploits, access credentials, or tools that enable misuse.
  • Please notify VIVAVIS immediately if you inadvertently gain access to personal data, trade secrets, access credentials, or other sensitive information.
  • Delete data obtained without authorization following consultation and as soon as it is no longer required for documentation and auditing purposes.

7. Coordinated publication

Please treat technical details regarding a reported vulnerability as confidential, at least initially, and coordinate any intended publication with VIVAVIS.

VIVAVIS shall not unduly delay a coordinated publication. The timing, content, and scope of a publication shall be determined on a risk-based approach and shall, in particular, take into account:

  • the availability of effective remedies or risk mitigation measures,
  • the risk to affected users,
  • the complexity of the fix,
  • Dependencies on third-party components,
  • and, where applicable, statutory or regulatory requirements.

The name or alias of the reporting person is published only with their prior consent.

8. Responsible security research

Insofar as the person reporting the matter:

  • acts in good faith,
  • complies with the requirements of these guidelines,
  • only compromises VIVAVIS software to the necessary extent,
  • does not pursue any intention of causing harm, engage in any attempt at enriching themselves or extorting money,
  • and promptly reports identified vulnerabilities to VIVAVIS on a confidential basis

VIVAVIS will, in principle, neither file a criminal complaint nor assert civil claims, based solely on the conduct of this responsible security research.

This statement:

  • does not constitute permission for unlawful or bad-faith acts,
  • does not grant access to third-party systems or data,
  • does not bind law enforcement agencies or other third parties,
  • and does not apply in cases of intentional harm, extortion, data misuse, publication in violation of agreed confidentiality, or other clearly abusive conduct.

If a notifying party has doubts as to whether a planned audit falls within the scope of this policy, the intended scope of the audit should be agreed upon with VIVAVIS beforehand.

9. Anonymous reports

Anonymous reports are accepted and reviewed based on the available information. However, without a means of contact, follow-up inquiries, status updates, and a final technical assessment may be difficult or impossible.

10. Previously known or resolved vulnerabilities

Reports concerning previously known or already remediated vulnerabilities are also accepted and assessed for their relevance to the specifically identified product and version.

If the vulnerability has already been remediated, VIVAVIS will — provided contact details were supplied and the information can be disclosed — specifically indicate which version or measure was used to resolve the issue.

In such cases, no further processing or recognition as a new vulnerability report generally takes place.

11. No bug bounty program

This policy does not give rise to any claim for remuneration, reimbursement of expenses, engagement, or other consideration. Any recognition or expression of thanks is voluntary and subject to prior agreement.

12. Changes to these guidelines

VIVAVIS may amend these guidelines to reflect changes in legal, technical, or organizational requirements.

Status: 05.08.2026
Responsible party: VIVAVIS AG, Nobelstraße 18, 76275 Ettlingen

Call now Call now
Call now +49 7243 218 0
Send Mail Send Mail
Send Mail info@vivavis.com
Locations & Contact VIVAVIS LOCATIONS
Locations & Contact Explore now