>> Product security

Product security.

Coordinated vulnerability disclosure policy

Security information

The security of our products is a top priority for voraus. We value the work of security researchers, customers and partners who help us find and fix vulnerabilities in order to make our products more secure.

The following policy applies to the voraus software products: voraus.core and voraus.pioneer including their packages. It does not cover our own IT, such as the company website or internal systems; if you are unsure, report it anyway and we will forward it internally.

How to report vulnerabilities?

If you discover a potential security vulnerability, please report it to psirt@vorausrobotik.com (German or English; PGP encryption recommended for confidential information).

We can receive encrypted email. Our public key is available at keys.openpgp.org, fingerprint 82D0 8724 AB92 DB55 999E 71EA F653 0DF7 81FD EF87.

The following details help us assess your report quickly:

  • your name and a way to contact you
  • the affected product and version
  • the type of vulnerability, if known
  • a technical description, with evidence where possible
  • reproduction steps or a proof of concept
  • the potential impact and the prerequisites for exploitation
  • a CVSS assessment, if you have one
  • whether and when you intend to publish

Incomplete reports are also accepted and will be followed up by the voraus Product Security Incident Response Team (PSIRT).

What happens with your report?

The voraus PSIRT investigates all reports of security problems that require a software update or other actions by the customer. This process includes:

  • We acknowledge receipt of your report (within 5 working days).
  • We determine whether and which products and versions are affected, and assess the severity.
  • We develop a fix, verify its effectiveness and make an update available.
  • We inform affected customers and, where the law requires it, the national CSIRT and ENISA within 24 hours: confidentially, naming the product and not you, and independently of any disclosure date we agree with you.
  • We keep you updated regularly.

Our commitments

If you follow this policy, we consider your research on our own products authorized. In that case we will not take legal action against you, we will work with you on the analysis and remediation, and we will treat your report as confidential (safe harbor).

Information on reported vulnerabilities is accessible only to the PSIRT members. We will ensure that the identity or other details of the security reporter are kept confidential and not published in any advisories unless explicitly requested. The same applies to any reports we are required to submit to authorities: they describe the product and the vulnerability, not the person who reported it.

We do not offer any remuneration for reports.

What we expect from you

  • Do not access data that is not yours, and do not alter or delete any data.
  • Do not carry out denial-of-service tests, and do not test third-party production systems.
  • Do not exploit the vulnerability beyond what is necessary to demonstrate it.
  • Do not disclose the vulnerability before the agreed date.
  • Comply with applicable law.

Disclosure and reporting

When a security update is available, we inform affected customers directly through the established support channel.

We agree the date of disclosure with you. Our standard period is 90 days from your report, and for complex vulnerabilities we can agree an extension. If the period expires and no update is available, we describe the vulnerability together with the protective measures that exist and state that the issue is still open.

Thank you for contributing to the security of our products.