SECURITY REPORTING
REPORT A SECURITY VULNERABILITY
Leifeld Metal Spinning GmbH is committed to ensuring the security of its products and protecting its customers and users from cybersecurity risks.
If you discover a potential security vulnerability in one of our products, we encourage you to report it to us. Your report helps us identify, investigate and address potential security issues in a timely and responsible manner.
This page describes our coordinated vulnerability disclosure process and provides a secure way to report potential vulnerabilities.
VULNERABILITY DISCLOSURE POLICY
1. Vulnerability Management
Leifeld Metal Spinning GmbH has established processes for receiving, assessing and addressing security vulnerabilities affecting its products.
Reported vulnerabilities are reviewed by the responsible teams and assessed based on their potential security impact. Where necessary, appropriate measures are taken to remediate or mitigate confirmed vulnerabilities and to provide relevant security information or updates to affected users.
2. Scope
This policy applies to products with digital elements manufactured or provided by Leifeld Metal Spinning GmbH, including associated software and digital components for which Leifeld Metal Spinning GmbH is responsible.
When submitting a report, please identify the affected product and, where possible, provide the product name, model, software or firmware version and any other information that helps us identify the affected component.
3. Out of Scope
This reporting channel is intended specifically for potential security vulnerabilities affecting our products.
Please do not use this reporting channel for:
- general product or customer support requests;
- vulnerabilities for which a security advisory or remediation has already been published by us;
- social engineering or phishing attempts impersonating Leifeld Metal Spinning GmbH;
- reports generated solely by automated vulnerability scanning tools without further validation; or
- issues that do not have a security impact.
For general product or service enquiries, please use our regular contact or support channels.
4. Handling of Vulnerability Reports
After receiving your report, we will review the information provided and assess the reported issue.
We may contact you using the email address provided in the form if additional information is required to investigate or reproduce the issue.
If a security vulnerability is confirmed, we will take appropriate measures to remediate or mitigate the vulnerability. Where appropriate, we may coordinate the handling and disclosure of the vulnerability with the reporter and other relevant parties.
Information about confirmed and remediated vulnerabilities may be published in a security advisory where appropriate.
5. Responsible Disclosure
We appreciate the efforts of security researchers and others who responsibly report potential vulnerabilities to us.
When investigating a potential vulnerability, we ask you to:
- act in good faith and avoid unnecessary access to data or systems;
- not access, modify, copy or delete data beyond what is necessary to demonstrate the vulnerability;
- avoid actions that could disrupt or negatively affect our products, systems, services or users;
- provide sufficient information to allow us to understand and reproduce the issue; and
- give us reasonable time to investigate and address the vulnerability before publicly disclosing details that could put our customers or users at risk.
We ask that you do not exploit a vulnerability beyond what is reasonably necessary to demonstrate its existence.
6. Bug Bounty
Leifeld Metal Spinning GmbH does not currently operate a bug bounty program. Submitting a vulnerability report does not create an entitlement to financial or other compensation.
7. Privacy
Personal data submitted through the reporting form will be processed for the purpose of receiving, assessing, investigating and responding to security vulnerability reports and, where applicable, fulfilling our legal obligations.
For further information about how we process personal data and your rights, please see our Privacy Policy.
REPORT A VULNERABILITY
Please provide as much information as possible to help us assess and investigate your report.