Reporting Chain
CRA-Compliant Reporting of Security Incidents
Use this simple reporting channel to report security incidents and vulnerabilities quickly and in compliance with the law.
1. Purpose
Integrated Dynamics Engineering GmbH places great importance on the security of its products and welcomes the responsible reporting of security vulnerabilities by customers, partners, security researchers, and other third parties.
This Vulnerability Disclosure Policy describes how potential vulnerabilities in products of Integrated Dynamics Engineering GmbH can be reported and how such reports are handled.
This policy supports the requirements of the Cyber Resilience Act (CRA) regarding a central point of contact for vulnerability reports and a documented process for coordinated vulnerability disclosure.
2. Scope
This policy applies to all products with digital elements developed or provided by Integrated Dynamics Engineering GmbH, including but not limited to:
- Robot controllers
- Wafer handlers
- Prealigners
- Controller systems
- Firmware
- Software applications
- Visualization systems
- Communication interfaces
3. Contact for Vulnerability Reports
Security-related information can be reported to the following contact address:
Email: csirt@ideworld.com
Alternatively, reports may be submitted in writing to Integrated Dynamics Engineering GmbH.
Current contact information is also available through the published security.txt file. The VDMA guidance recommends a central security contact as a "Single Point of Contact."
4. Information to Include in a Report
To enable prompt processing, reporters are encouraged to provide the following information whenever possible:
- Name and contact details of the reporter
- Affected product
- Product version
- Affected component
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Proof of Concept (PoC) or screenshots (if available)
- Known mitigations
Incomplete reports will also be reviewed.
5. Handling of Reports
Upon receipt of a report, the following process applies:
Acknowledgement of Receipt
Integrated Dynamics Engineering GmbH will generally acknowledge receipt of a vulnerability report within seven calendar days. The VDMA recommendations define an acknowledgement within seven days as a target value.
Assessment
The report will be reviewed by the PSIRT with regard to:
- Relevance
- Reproducibility
- Whether an isel product is affected
- Security impact
Communication
During the analysis, the PSIRT may request additional information.
The reporter will be informed about the status of the investigation where possible and appropriate.
6. Coordinated Disclosure
Integrated Dynamics Engineering GmbH follows the principle of responsible vulnerability disclosure.
We ask reporters to:
- Treat vulnerabilities confidentially at first
- Refrain from publicly disclosing information before a joint assessment has been completed
- Allow the manufacturer sufficient time for analysis and remediation
Once appropriate mitigations are available, a coordinated public disclosure may take place.
7. Good-Faith Security Research
Integrated Dynamics Engineering GmbH welcomes security research conducted in good faith.
Security researchers are considered to act in accordance with this policy when they:
- Do not modify or delete data
- Do not publish personal data
- Do not intentionally disrupt services
- Do not endanger customer installations
- Investigate vulnerabilities solely for the purpose of reporting them
8. Activities Not Covered
The following activities are not covered by this policy:
- Social engineering against employees
- Phishing campaigns
- Denial-of-Service (DoS) attacks
- Attacks against customer systems
- Physical tampering with third-party installations
- Publication of confidential information without prior coordination
9. Publication of Security Advisories
For confirmed and relevant vulnerabilities, Integrated Dynamics Engineering GmbH may publish Security Advisories.
Such advisories may include:
- Advisory ID
- Affected products
- Affected versions
- Risk assessment
- Remediation measures
- Available updates
- Workarounds
10. Data Protection
Personal data will be used exclusively for processing vulnerability reports and will be handled in accordance with applicable data protection regulations.
11. Disclaimer
The receipt of a vulnerability report does not create any obligation to provide compensation, rewards, or bug bounty payments.
Integrated Dynamics Engineering GmbH reserves the right to evaluate each report individually and determine appropriate actions.