cyber-security-header

Coordinated Vulnerability Disclosure Policy

Purpose

Bender GmbH & Co. KG is committed to maintaining the security of its products, services, and IT infrastructure. Security vulnerabilities can pose significant risks if they are not identified and addressed in a timely and responsible manner.

This Coordinated Vulnerability Disclosure (CVD) Policy defines a clear and structured process for reporting security vulnerabilities. It enables Bender to investigate reported issues, assess their impact, and implement appropriate remediation measures before any public disclosure takes place.

In Scope

The following components are explicitly considered within the scope of this policy:

  • Product software and firmware
  • Backend systems
  • IT infrastructure operated by Bender
  • All Bender cloud services and APIs
  • Corporate websites (e.g. bender.de, bender.es, bender‑cn.com, …)

Out of Scope

The following activities and systems are excluded from this policy and should not be reported under this CVD process:

  • Denial‑of‑Service attacks through traffic flooding
  • Customer‑side misconfigurations
  • Social engineering attacks
  • Physical attacks requiring direct device access

Reporting a Vulnerability

Bender encourages responsible disclosure and provides several secure channels to report suspected security vulnerabilities.

Secure Communication

For confidential communication, Bender provides a PGP public key. Reporters are strongly encouraged to use encrypted communication whenever possible, especially when sharing sensitive technical details.

Disclosure Guidelines

To support a responsible and efficient disclosure process, reporters are requested to follow these guidelines:

  • Provide sufficient technical information to allow reproduction of the issue (e.g.
    screenshots, logs, proof‑of‑concept code).
  • Do not disclose the vulnerability publicly or to third parties until Bender has confirmed
    remediation.
  • Do not engage in malicious activities, including data destruction, unauthorized data
    access, or service disruption.

Submitting a Report - General Requirements

Each vulnerability report should meet the following minimum requirements:

  • A clear, detailed, and reproducible description of the vulnerability and its potential impact.
  • All necessary test data, test accounts, and steps required for verification.
  • One vulnerability per report; unrelated issues must be submitted separately.
  • Written, step‑by‑step instructions describing how to reproduce the issue.

Bug Bounty Program

Bender does not operate a bug bounty or paid vulnerability reward program.

Due to an increasing number of automated and non‑substantiated vulnerability submissions, including reports generated by automated or AI‑based tools without sufficient technical validation, Bender focuses its resources exclusively on coordinated and responsible disclosure.

Submitting a vulnerability report under this policy does not entitle the reporter to financial compensation. Reports are assessed solely based on their technical relevance, validity, and impact.

Response and Handling

Bender aims to respond to vulnerability reports within defined timeframes:

  • Acknowledgement: within 3 working days
  • Initial technical assessment: within 15 working days

All reported vulnerabilities are handled through an established internal vulnerability and incident management process. Severity assessment  and prioritization are performed internally based on risk and technical impact.

Coordination & Disclosure

Bender follows a coordinated disclosure approach to minimize risk and ensure transparency:

  • Vulnerabilities are remediated before public disclosure whenever possible.
  • Disclosure is coordinated with the reporting party where feasible.
  • A maximum disclosure timeline of 90 days applies unless otherwise agreed.

Publication & Advisories

Security advisories and CVE information are published publicly by Bender’s partner CERT@VDE.

Safe Harbor

Bender provides a Safe‑Harbor assurance for security research conducted in good faith. We will not pursue legal action against researchers who:

  • Act responsibly and in good faith
  • Avoid testing on productive customer systems
  • Do not violate data protection laws
  • Do not exploit vulnerabilities beyond what is necessary for verification

Recognition

Bender values responsible security research and may publicly acknowledge contributors, for example through a Hall of Fame, unless anonymity is explicitly requested.

Policy Maintenance

This policy is reviewed regularly and updated as necessary to reflect changes in products, services, and regulatory requirements.

 

Reporting Channels

Depending on the affected area, vulnerabilities can be reported via the following channels: