Coordinated Vulnerability Disclosure Policy of the Strama Group

 

Purpose

The Strama Group is committed to handling vulnerabilities in its products, systems, and services responsibly, in a coordinated manner, and with the aim of minimizing risks to customers, business partners, employees, and other affected parties. This policy describes the process for reporting, handling, and disclosing vulnerabilities.

 

Scope

This policy applies to all products, systems, and services developed, manufactured, integrated, operated, maintained, or provided by companies of the Strama Group.

It further applies to all components, applications, technologies, interfaces, access mechanisms, networks, and other technical assets that form part of, or are required for the development, provision, operation, maintenance, or administration of, such products, systems, or services. This includes, but is not limited to, hardware, software, firmware, web applications, customer portals, APIs, communication systems, network infrastructure, remote access and administrative access mechanisms, as well as integrated third-party, supplier, and open-source components.

This policy also applies to all IT, OT, and cloud infrastructures operated or managed by the Strama Group, including the associated systems, networks, platforms, services, and access mechanisms.

This policy does not apply to third-party systems, products, or services that are outside the Strama Group's area of control or responsibility.

 

Responsible Security Research

The Strama Group welcomes the responsible reporting of vulnerabilities.

Without the prior explicit authorization of the Strama Group, security assessments, vulnerability scans, penetration testing, exploitation attempts, social engineering, physical attacks, or any other activities intended to identify or exploit vulnerabilities in products, systems, or services of the Strama Group are not permitted.

This does not affect the reporting of vulnerabilities identified during the intended use, operation, maintenance, or on the basis of publicly available information.

Security assessments of products or systems owned or operated by customers or other third parties may only be performed with their prior explicit authorization. This policy does not constitute authorization to access or test third-party systems.

When reporting a vulnerability, information may only be processed, stored, or shared to the extent necessary to document the vulnerability.

Vulnerability reports associated with extortion attempts, financial demands, or threats of premature public disclosure will not be considered responsible disclosures under this policy.

 

Cooperation (Safe Harbor)

The Strama Group will cooperate in good faith with individuals who report vulnerabilities responsibly.

The Strama Group currently does not operate a bug bounty, reward, or compensation program.

Provided that this policy has been followed and the Strama Group has no indication of intentional or grossly negligent violations of applicable law, the Strama Group generally does not intend to initiate or support legal action against a reporting individual solely on the basis of a responsible vulnerability disclosure.

This applies in particular where the reporting individual:

  • acts in good faith;
  • complies with applicable laws and this policy;
  • does not cause damage to or disruption of products, systems, services, or data;
  • does not compromise the availability, integrity, or confidentiality of products, systems, or information belonging to the Strama Group;
  • does not disclose vulnerabilities prematurely or without coordination;
  • does not unlawfully store, process, publish, or disclose confidential, personal, or other non-public information; and
  • respects the rights, safety, and privacy of third parties.

Nothing in this policy expressly or implicitly authorizes violations of applicable law, contractual obligations, or the rights of third parties. The Strama Group cannot provide protection against claims or legal action by third parties where their systems or data have been affected without their authorization.

 

 

Handling of Vulnerability Reports

Every vulnerability report is carefully reviewed.

The handling process generally consists of the following steps:
 

1. Reporting

Vulnerabilities may be reported using the contact methods provided in this policy.

The Strama Group will make reasonable efforts to acknowledge receipt of a report in a timely manner.

Where possible, a report should include:

  • a description of the vulnerability;
  • the affected product or system;
  • software, firmware, or version information (if known);
  • steps to reproduce the issue;
  • the potential impact; and
  • a proof of concept (PoC), log files, or screenshots (if available).
     

2. Analysis

The Strama Group will analyze the report, assess the associated risk, and request additional information where necessary.
 

3. Remediation

Appropriate protective, mitigating, or corrective measures will be developed and implemented.

Where possible and appropriate, the Strama Group will keep the reporting individual informed of the progress.

Due to the technical complexity of special-purpose machinery and customer-specific integrations, longer remediation timelines may be required.
 

4. Coordinated Disclosure

The Strama Group follows a responsible and risk-based approach to vulnerability disclosure.

For customer-specific systems or individual installations, affected customers will be informed directly and provided with appropriate protective or corrective measures.

Public disclosure will generally take place only after appropriate protective or corrective measures have been made available, and only where multiple systems or customers may be affected, where there is an overriding security interest, or where disclosure is required by law.

No customer-specific, confidential, or otherwise sensitive information will be disclosed.

Where appropriate, CVE identifiers may be assigned, and vulnerabilities may be assessed using the current version of the Common Vulnerability Scoring System (CVSS). Where required by law, the competent authorities or Computer Emergency Response Teams (CERTs) may be notified.
 

Reporting Vulnerabilities

Vulnerability reports may be submitted in either German or English. Anonymous reports are accepted; however, this may limit the ability to request additional information or provide feedback.

The use of the published PGP key is strongly recommended when transmitting sensitive information.
 

E-Mail
security@strama-mps.de

PGP-Key
https://strama-mps.de/.well-known/security-strama-mps-de.asc

PGP-Fingerprint

D34B 29B1 5998 80E4 85D2 CA2B A7AF 913F D6FF D301

security.txt
https://strama-mps.de/.well-known/security.txt

Personal data submitted as part of a vulnerability report will be processed solely for the purpose of handling the report and fulfilling applicable legal obligations.

 

Scope of this Policy

This policy applies to the following companies of the Strama Group:

  • Strama-MPS Maschinenbau GmbH & Co. KG
  • F & K DELVOTEC Bondtechnik GmbH
  • AuE Kassel GmbH
     

Version: 20 July 2026