
Bender GmbH & Co. KG is committed to maintaining the security of its products, services, and IT infrastructure. Security vulnerabilities can pose significant risks if they are not identified and addressed in a timely and responsible manner.
This Coordinated Vulnerability Disclosure (CVD) Policy defines a clear and structured process for reporting security vulnerabilities. It enables Bender to investigate reported issues, assess their impact, and implement appropriate remediation measures before any public disclosure takes place.
The following components are explicitly considered within the scope of this policy:
The following activities and systems are excluded from this policy and should not be reported under this CVD process:
Bender encourages responsible disclosure and provides several secure channels to report suspected security vulnerabilities.
For confidential communication, Bender provides a PGP public key. Reporters are strongly encouraged to use encrypted communication whenever possible, especially when sharing sensitive technical details.
To support a responsible and efficient disclosure process, reporters are requested to follow these guidelines:
Each vulnerability report should meet the following minimum requirements:
Bender does not operate a bug bounty or paid vulnerability reward program.
Due to an increasing number of automated and non‑substantiated vulnerability submissions, including reports generated by automated or AI‑based tools without sufficient technical validation, Bender focuses its resources exclusively on coordinated and responsible disclosure.
Submitting a vulnerability report under this policy does not entitle the reporter to financial compensation. Reports are assessed solely based on their technical relevance, validity, and impact.
Bender aims to respond to vulnerability reports within defined timeframes:
All reported vulnerabilities are handled through an established internal vulnerability and incident management process. Severity assessment and prioritization are performed internally based on risk and technical impact.
Bender follows a coordinated disclosure approach to minimize risk and ensure transparency:
Security advisories and CVE information are published publicly by Bender’s partner CERT@VDE.
Bender provides a Safe‑Harbor assurance for security research conducted in good faith. We will not pursue legal action against researchers who:
Bender values responsible security research and may publicly acknowledge contributors, for example through a Hall of Fame, unless anonymity is explicitly requested.
This policy is reviewed regularly and updated as necessary to reflect changes in products, services, and regulatory requirements.
Depending on the affected area, vulnerabilities can be reported via the following channels: