Coordinated vulnerability disclosure policy
Nöding Messtechnik GmbH, Oldenfelder Bogen 29 D-22143 Hamburg
Version 1.0, last modified 10 September 2026
1. Scope
This policy applies to all products with digital elements of Nöding Messtechnik GmbH and to the IT infrastructure of Nöding Messtechnik GmbH. It describes how to report a vulnerability to us, how we handle your report, and under which conditions we disclose vulnerabilities.
2. Reporting
Please send reports to vulnerability@noeding-messtechnik.de. This address is our single point of contact and covers vulnerabilities in our products as well as in our website and IT infrastructure.
You can also reach us by phone at +49 40 675851-0, Monday to Thursday from 08:00 to 15:00 and Friday from 08:00 to 12:00 (time zone Europe/Berlin), except on public holidays in Hamburg.
We accept email addresses and telephone numbers as contact options for follow-up questions.
Reporting without disclosing your identity is possible; the details are set out in section 6.
3. Valid vulnerabilities
We treat a report as a valid vulnerability if it concerns a product or the infrastructure of Nöding Messtechnik GmbH, relates to information that is not publicly known, and contains more than the uncommented output of an automated scan.
Reports that do not meet these conditions are still reviewed to the best of our ability, and we inform you of the outcome.
4. Handling and response times
We respond to every report, and to every addition to a report already received, within five working days. This response is written by a person; an automated acknowledgement does not take its place.
After the technical review you will receive substantive feedback within ten working days. It contains at least one of the following: confirmation or reasoned rejection of the reported vulnerability, specific questions about the matter, or an explanation of why the review takes longer.
We remain available to you as a point of contact until the process is complete.
5. Confidentiality and data protection
We treat incoming reports confidentially as far as legally permissible. The only exception is information required for disclosure under section 7.
We do not disclose the reporting person's personal data to third parties without their explicit consent unless we are required to do so by law or by an order of a public authority or a court.
The notifications to the responsible national CSIRT and to ENISA under Article 14 of Regulation (EU) 2024/2847 concern the vulnerability, not you as a person.
Further information on processing is available in our privacy policy.
6. Anonymous reports
You do not have to give us your name. A report from an anonymous but reachable email address is treated like any other report; we do not ask who is behind it. The commitments in section 4 apply to such reports without restriction.
Complex matters usually require follow-up questions and additional material. If we receive a report with no contact option at all, we cannot ask those questions. Such reports can therefore only be processed to a limited extent and possibly not at all, and we cannot meet the response times set out in section 4 for them.
7. Disclosure
Disclosure takes place at least through the European Vulnerability Database (EUVD) operated by ENISA; we arrange the entry in coordination with the responsible national CSIRT or with ENISA.
In the case of actively exploited vulnerabilities we notify the national CSIRT responsible for us without undue delay and coordinate all further steps, including schedules, with it.
8. What we expect from you
We ask you to observe the following:
Do not exploit the vulnerability beyond what is needed to demonstrate it, and do not cause damage. Do not attack our systems, in particular no social engineering, no spam, and no denial-of-service or brute-force attacks. Do not modify, compromise or delete third-party data. Do not make tools for exploiting the vulnerability available, whether for payment or free of charge. Allow us reasonable time for remediation before publishing; we normally ask for 90 days from the confirmation of the vulnerability. We expect all parties to treat each other with respect.
9. Legal assurance
As long as you comply with this policy, we will refrain from criminal charges and civil claims against you. This does not apply where criminal intent has been or is being pursued.
We do not require a non-disclosure agreement.
If you do not observe the expectations set out in section 8, we will still handle your report to the best of our ability. The assurance in the first paragraph of this section does not apply in that case.
10. Bounties
Nöding Messtechnik GmbH does not pay bounties for reported vulnerabilities and does not maintain a public acknowledgements page.
11. Completion of the process
The process is complete when one of the following applies:
- The information in the report has proven to be unfounded.
- The vulnerability in a service has been fixed and publicly disclosed.
- The vulnerability has been fixed or effectively mitigated by an update and publicly disclosed.
- No answer to technical or content-related questions has been received for at least 30 days, so that further processing is not possible.
- The vulnerability is publicly known and, in coordination with the responsible national CSIRT, it can no longer be assumed that it will be fixed or mitigated.
For reports that are not anonymous, we inform you of the completion without undue delay.
12. Changes to this policy
We review this policy at least once a year and adapt it where necessary. The version published on this page, bearing the modification date stated above, is authoritative.