CVD Policy
Coordinated Vulnerability Disclosure (CVD) Policy
1. Purpose
LayTec is committed to the responsible handling of reported cybersecurity vulnerabilities affecting its products, services, and IT systems.
This policy describes the process for reporting, handling, and disclosing vulnerabilities as part of a Coordinated Vulnerability Disclosure (CVD) process.
Its objective is the timely identification, assessment, remediation, and responsible disclosure of vulnerabilities to improve the cybersecurity of our customers, partners, and products.
2. Scope
This policy applies to:
LayTec products and software
LayTec cloud services and web applications
Publicly accessible IT systems operated by LayTec
Infrastructure components under the responsibility of LayTec
The following are out of scope:
Physical security issues
Social engineering attacks
Spam or denial-of-service (DoS) testing
Activities that intentionally impair the availability of systems
3. Reporting a vulnerability
Security vulnerabilities may be reported through either of the following channels:
Product Security Insident Response Team Mail: psirt@laytec.de
Company Security Incident Response Teams Mail: csirt@laytec.de
Alternatively, you can use the vulnerability reporting form at the end of this webpage. Reports submitted through the web form may be made anonymously.
4. Information to include
To help us investigate your report efficiently, please provide, where possible:
The affected product or system
Product version
A description of the vulnerability
The potential impact
Steps to reproduce the issue
Proof of Concept (PoC), if available
Your contact details for follow-up questions
Anonymous reports are accepted. Please note that anonymous reports may limit our ability to request additional information and could therefore affect the investigation process.
5. Response times
LayTec is committed to responding to vulnerability reports in a timely and transparent manner.
Our response targets are as follows:
We will provide a personal acknowledgement of receipt within 5 business days.
We aim to provide an initial technical response within 10 business days.
During ongoing investigations, we will provide status updates at least every 10 business days.
Please note that automatically generated acknowledgements do not replace a personal response from our security team.
6. Confidentiality
LayTec treats all vulnerability reports confidentially. Personal information provided by reporters will not be published or shared with third parties without explicit consent, unless required by applicable law.
7. Good faith reporting
LayTec welcomes responsible vulnerability reporting.
Provided that the reporter:
acts in good faith,
does not manipulate or destroy data,
does not disrupt systems or services,
does not disclose confidential information without authorization,
does not exploit the vulnerability beyond what is reasonably necessary to demonstrate its existence,
LayTec will not initiate legal action solely on the basis of the submitted vulnerability report
8. Guidelines for security researchers
We kindly ask security researchers to:
refrain from modifying customer or third-party data;
avoid causing damage to systems or services;
not perform denial-of-service or availability attacks;
not publicly disclose vulnerabilities before coordinated disclosure has been agreed with LayTec;
use identified vulnerabilities only to demonstrate their existence and not for any other purpose.
9. Vulnerability assessment
Each reported vulnerability is reviewed and assessed by LayTec.
The assessment considers, among other factors:
Reproducibility
Impact on confidentiality, integrity, and availability
Exploitability
Affected products
CVSS (Common Vulnerability Scoring System) rating
A vulnerability is considered confirmed once its existence has been successfully verified.
10. Vulnerability disclosure
LayTec follows the principles of Coordinated Vulnerability Disclosure. Confirmed vulnerabilities will be disclosed in a coordinated manner after appropriate remediation or mitigation measures have been developed and made available.
Where a vulnerability is subject to mandatory reporting under Article 14 of the Cyber Resilience Act, LayTec will submit the required notification once via the ENISA Single Reporting Platform. The platform handles the further distribution to the competent authorities in accordance with the applicable CRA reporting procedure.
LayTec aims to publish a Security Advisory within 90 calendar days after confirming a vulnerability. Where necessary, the disclosure timeline may be adjusted to allow for appropriate remediation, customer protection, or regulatory requirements.
11. Communication with authorities and CSIRTs
In the event of an actively exploited vulnerability or a severe cybersecurity incident that is subject to mandatory reporting under Article 14 of the Cyber Resilience Act, LayTec will submit the required notification once via the ENISA Single Reporting Platform.
The platform handles the further distribution of the notification to the competent authorities in accordance with the applicable CRA reporting procedure.
12. Acknowledgement of reporters
With the reporter's consent, LayTec may acknowledge individuals who responsibly disclose security vulnerabilities on a future Hall of Fame page.
13. Closure of the disclosure process
A Coordinated Vulnerability Disclosure process is considered complete when:
the vulnerability has been remediated and publicly disclosed;
appropriate mitigation measures have been implemented;
the reported issue has been determined not to be a security vulnerability; or
no further investigation or action is possible.
14. Policy maintenance
This policy is reviewed at least annually and updated whenever necessary.
openPGP public key
Fingerprint:
CSIRT
530A 1893 583A 266D 0F0B 8A6B 1098 1790 C54C 9C43
PSIRT
8DEE 90DD FD63 211F 4E0B 62E2 6E50 CBF6 9288 836E
Contact
We look forward to hearing from you and will try to answer your questions or respond to your message as best we can. Please use one of the following contact options.