IDE Services

Reporting Chain

CRA-Compliant Reporting of Security Incidents

Use this simple reporting channel to report security incidents and vulnerabilities quickly and in compliance with the law.


1. Purpose

Integrated Dynamics Engineering GmbH places great importance on the security of its products and welcomes the responsible reporting of security vulnerabilities by customers, partners, security researchers, and other third parties.

This Vulnerability Disclosure Policy describes how potential vulnerabilities in products of Integrated Dynamics Engineering GmbH can be reported and how such reports are handled.

This policy supports the requirements of the Cyber Resilience Act (CRA) regarding a central point of contact for vulnerability reports and a documented process for coordinated vulnerability disclosure.


2. Scope

This policy applies to all products with digital elements developed or provided by Integrated Dynamics Engineering GmbH, including but not limited to:

  • Robot controllers
  • Wafer handlers
  • Prealigners
  • Controller systems
  • Firmware
  • Software applications
  • Visualization systems
  • Communication interfaces

3. Contact for Vulnerability Reports

Security-related information can be reported to the following contact address:

Email: csirt@ideworld.com

Alternatively, reports may be submitted in writing to Integrated Dynamics Engineering GmbH.

Current contact information is also available through the published security.txt file. The VDMA guidance recommends a central security contact as a "Single Point of Contact."


4. Information to Include in a Report

To enable prompt processing, reporters are encouraged to provide the following information whenever possible:

  • Name and contact details of the reporter
  • Affected product
  • Product version
  • Affected component
  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Proof of Concept (PoC) or screenshots (if available)
  • Known mitigations

Incomplete reports will also be reviewed.


5. Handling of Reports

Upon receipt of a report, the following process applies:

Acknowledgement of Receipt

Integrated Dynamics Engineering GmbH will generally acknowledge receipt of a vulnerability report within seven calendar days. The VDMA recommendations define an acknowledgement within seven days as a target value.

Assessment

The report will be reviewed by the PSIRT with regard to:

  • Relevance
  • Reproducibility
  • Whether an isel product is affected
  • Security impact

Communication

During the analysis, the PSIRT may request additional information.

The reporter will be informed about the status of the investigation where possible and appropriate.


6. Coordinated Disclosure

Integrated Dynamics Engineering GmbH follows the principle of responsible vulnerability disclosure.

We ask reporters to:

  • Treat vulnerabilities confidentially at first
  • Refrain from publicly disclosing information before a joint assessment has been completed
  • Allow the manufacturer sufficient time for analysis and remediation

Once appropriate mitigations are available, a coordinated public disclosure may take place.


7. Good-Faith Security Research

Integrated Dynamics Engineering GmbH welcomes security research conducted in good faith.

Security researchers are considered to act in accordance with this policy when they:

  • Do not modify or delete data
  • Do not publish personal data
  • Do not intentionally disrupt services
  • Do not endanger customer installations
  • Investigate vulnerabilities solely for the purpose of reporting them

8. Activities Not Covered

The following activities are not covered by this policy:

  • Social engineering against employees
  • Phishing campaigns
  • Denial-of-Service (DoS) attacks
  • Attacks against customer systems
  • Physical tampering with third-party installations
  • Publication of confidential information without prior coordination

9. Publication of Security Advisories

For confirmed and relevant vulnerabilities, Integrated Dynamics Engineering GmbH may publish Security Advisories.

Such advisories may include:

  • Advisory ID
  • Affected products
  • Affected versions
  • Risk assessment
  • Remediation measures
  • Available updates
  • Workarounds

10. Data Protection

Personal data will be used exclusively for processing vulnerability reports and will be handled in accordance with applicable data protection regulations.


11. Disclaimer

The receipt of a vulnerability report does not create any obligation to provide compensation, rewards, or bug bounty payments.

Integrated Dynamics Engineering GmbH reserves the right to evaluate each report individually and determine appropriate actions.

Report a security vulnerability


Affected product


Description of the vulnerability


Evidence





*Required Fields