Product Security
Security is a high priority at GEORG – including in our products. If you have discovered a vulnerability in a GEORG product, we welcome your report and thank you for giving us the opportunity to fix it before it can cause harm to others.
Contact
Below we answer the most frequently asked questions about reporting vulnerabilities and the process that follows.
Please report the vulnerability to us confidentially by email at psirt@georg.com. You can encrypt your message using our PGP key (available at https://www.georg.com/.well-known/security.txt). We will confirm receipt within 5 business days.
The more detail you provide, the faster we can assess the vulnerability. Helpful information includes:
- Affected product and version
- Description of the vulnerability and steps to reproduce it
- Potential impact
- Evidence such as screenshots or PoC code – please submit encrypted
- Your contact details for follow-up questions – optional, anonymous reports are also processed
No. Anonymous reports are also processed. However, if you would like updates on the status of your report or recognition once it is resolved, we will need a way to contact you.
We confirm receipt, assess the vulnerability, and keep you informed of progress. We coordinate the disclosure timing with you and ask that you not publish any details until we have agreed on this together. The standard period for this is 90 days from receipt of your report.
No – as long as you act in good faith and follow the rules of engagement listed below, GEORG commits to not taking legal action against you. The rules of engagement are:
- Report the discovered vulnerability as early as possible to minimize the risk of exploitation
- Keep the discovery confidential until a disclosure date has been jointly agreed
- Do not actively access customer systems without the explicit permission of the plant operator
- Do not modify, delete, or make unauthorized copies of data beyond what is necessary to reproduce the issue
- Do not use destructive techniques (brute force, denial-of-service, social engineering)
Vulnerabilities in third-party products, non-reproducible findings, purely theoretical scenarios without a recognizable attack path, as well as phishing, social engineering, and denial-of-service attacks are outside the scope of this policy.
Yes. You can alternatively contact the BSI (German Federal Office for Information Security): bsi.bund.de – Schwachstellenmeldungen (https://www.bsi.bund.de/DE/IT-Sicherheitsvorfall/IT-Schwachstellen/Schwachstellenmeldungen/Schwachstellenmeldungen.html)
For questions or comments regarding this policy, please also contact psirt@georg.com.