Vulnerability reporting
Detectomat GmbH, Detectomat Systems GmbH and Simax Electronics GmbH (collectively Detectomat Group) encourage users and researchers to report security issues. Please note that quality and warranty issues should be reported to the regular channels:
https://www.detectomat.com/en/contact/customer-service-hotline
Our Commitment
Detectomat Group welcomes vulnerability reports from security researchers, customers, partners, industry groups and CERTs (Computer Emergency Response Teams) — regardless of service contracts or product lifecycle status. Anonymous reports are also welcome.
If you believe that you have identified a potential security vulnerability or incident related to any Detectomat Group product, software, service or product related infrastructure, please keep the following points in mind when contacting us via
What you can expect from us
- Acknowledgement of your report within 2 working days (excluding weekends and public holidays in Schleswig-Holstein, Germany)
- An estimated time frame for addressing the reported vulnerability
- Coordination of the response with our engineering and development teams, with status updates as relevant information becomes available
- Notification once the vulnerability has been fixed
What we ask your for
- Treat the vulnerability as confidential until we have made a fix available, and do not share or publicise it with third parties
- Do not cause harm to Detectomat Group, our customers or others
- Do not compromise the privacy or safety of our customers or the operation of our services
- Do not violate any law
Immediate public disclosure puts our customers' systems at unnecessary risk, so we strongly encourage coordinated disclosure. As long as the points above are respected, Detectomat Group will not pursue claims against the reporting party.
Responsible Submissions
We ask that all submissions to us are made in good faith and that the following points are considered and followed when making a report to us:
- We may only consider reports written in German or English
- Identify the affected product including
- model & firmware version (if available),
- URL address for website vulnerabilities and
- version details for software products.
- A description of the vulnerability including if applicable
- proof-of-concept
- exploit code or network traces
- physical vulnerability
- Public references, if there is any. Please indicate if the vulnerability has already been publicly disclosed and by whom.
If a large amount of data needs to be submitted, please open a report with us so we may offer an easy-to-use service for data transfer.
Thank you for helping us improve the security and safety of our products, our customers and the wider community.