Coordinated Vulnerability Disclosure Policy (CVD)

Report a Vulnerability

1. Purpose

This policy establishes a secure, transparent and legally compliant process for reporting security vulnerabilities in SYSGO's software products.

Our goal is to protect customers and, subsequently, end users while allowing researchers to contribute to product security.


2. Scope

This policy applies to all security vulnerabilities in currently supported software products, services and infrastructure of SYSGO. Vulnerabilities in third-party products not developed or maintained by SYSGO GmbH, unless explicitly covered by a contractual agreement, are out of scope.


3. Reporting Channels

Vulnerability reports must include:

  • Product / Product version affected / configuration details
  • Complete technical description of the potential vulnerability, including any related known exploits, Proof-of-concept, Impact assessment
  • Any public information already published or planned to be published (CVE, academic paper publication, etc.).
  • How and when the the potential vulnerability was discovered.
  • Your contact information 

For confidential reporting of product security vulnerabilities, please use our PGP key to encrypt the message to psirt@sysgo.com

Contact information is also available in https://www.sysgo.com/.well-known/security.txt

PGP Fingerprint: 95470823A191AD95D0B76E19B06CE47FB5D62CA3


4. Our Commitments

Initial Assessment: We will assess your report on our software products, services and infrastructure and provide a timeline for resolution.
If you found a vulnerability in an IT system or IT product that does not relate to SYSGO products, report this to the owner of the system or the manufacturer.

Compliance: Our processes are set up to be aligned with our ISO 27001, ISO 9001 and GDPR compliance fundamentals.

No Public Disclosure: We will not publish CVEs, advisories or public acknowledgments. We prefer to maintain direct communication with our B2B customers. This ensures timely mitigation without public disclosure - this is taking CRA Article 2 (8) into account.

Bug Bounty Program: We do not support a monetary bug bounty program.


5. Your Commitments

Confidentiality: Do not disclose the issue. Disclosure will be organized by SYSGO after the mitigation or security update are available and communicated to our customers.

Responsible Testing: Do not take advantage of the security issue discovered, for example, by downloading more data than necessary to demonstrate the vulnerability, or by deleting/modifying data.

Legal Protection: Not covered or authorized by this policy are violations of privacy laws (e.g., GDPR) social engineering attacks, denial of service attacks,  physical site intrusion, spam, or applications of third parties.
We will not pursue legal action for good-faith reports compliant with this policy.


6. Disclosure Process

Fix Development: We release a patch or mitigation in a timely manner.

Communication: We will coordinate with affected customers to deploy fixes and provide guidance according to our contracts concerning products and projects which are referred to as "legacy" with respect to CRA. For CRA conform products communication will be done in a CRA conform way. SYSGO's PSIRT team will communicate back to the submitter and others where appropriate. 

No Public Acknowledgment: We will not publish researcher credits.


7. Legal Disclaimer

By submitting a vulnerability report, you agree to the terms of this CVD Policy and the Privacy Policy.

SYSGO reserves the right to modify these policies at any time.

Submission of a report does not create any contractual or legal obligations beyond those explicitly stated herein. 


Released 2026-09-15