Zum Inhalt springen

Coordinated Vulnerability Disclosure (CVD) Policy

Version: 1.0
Last updated: 16.07.2026
Manufacturer / Producer: Gira Giersiepen GmbH & Co. KG (Gira)

1. Purpose

Gira is committed to ensuring an appropriate level of cybersecurity for its products and related digital elements. As part of this commitment, Gira supports Coordinated Vulnerability Disclosure (CVD) and encourages security researchers, customers, and other stakeholders to responsibly report potential security vulnerabilities.

This policy describes how vulnerabilities can be reported to Gira, how reports are handled, and the principles under which coordinated disclosure is conducted.

2. Scope

This policy applies to security vulnerabilities affecting:

  • Products with digital elements developed and/or placed on the market by Gira, including embedded software, firmware, and associated applications.

  • Related digital services provided or operated by Gira that are directly connected to such products.

Out of scope are, in particular:

  • Security issues in systems or services not operated or controlled by Gira.

  • Vulnerabilities resulting solely from misconfiguration or use of unsupported third party components outside the responsibility of Gira.

  • Denial of Service testing, social engineering, physical attacks, or non technical attacks.

3. Reporting a vulnerability

Potential vulnerabilities should be reported using one of the following channels:

Reports should be submitted only in English or German in order to facilitate timely processing.

4. Information to include in the report

To enable efficient triage and analysis, reports should include, where available:

  • Identification of the affected Gira-Product, -Component, or -Service (including version information),

  • A clear description of the potential vulnerability and its potential impact,

  • Step by step instructions to reproduce the issue, using a non destructive proof of concept,

  • Any relevant logs, or test information (excluding unnecessary personal or sensitive data) and

  • Information on whether the vulnerability has been reported to or coordinated with other parties (e.g. CERTs or coordinators).

5. Rules for responsible testing – Code of Conduct

When researching and reporting vulnerabilities, Reporting Parties are expected to:

  • Act in good faith and in compliance with all applicable laws and regulations,

  • Avoid actions that could harm users, customers, or the availability, integrity, or confidentiality of systems,

  • Refrain from accessing, modifying, or deleting data beyond what is strictly necessary to demonstrate the vulnerability,

  • Avoid disruptive testing methods, including denial of service attacks or high intensity scanning,

  • Keep information about the vulnerability confidential until remediation and coordinated disclosure have been completed and

  • Respond to requests for further information within 30 days or the case may be closed.

6. Anonymous reporting and communication

Reports may be submitted without identifying information.

However, particularly in the case of complex vulnerabilities, it could be possible that additional explanations or documentation will be required during analysis. In this case processing is limited.

As the successful execution of the CVD process relies heavily on trust based and continuous communication with reporter, reports submitted without valid contact details may only be processed to a limited extent.

Providing contact information therefore significantly increases the likelihood of effective validation, remediation, and coordinated disclosure.

Gira will treat informations of Reporting Parties confidentially and use it solely for the purposes of vulnerability handling according to Privacy Information for Gira Vulnerability Management: https://www.gira.de/cybersecurity/privacy-polic

7. Handling of reports by Gira

Upon receipt of a vulnerability report that reasonably relates to products or services within scope, Gira will make reasonable efforts to:

  • Acknowledge receipt of the report within five (5) working days[KT2.1], excluding weekends and public holidays, applicable in North Rhine-Westphalia, Germany,

  • Assess and triage the reported vulnerability in a timely manner,

  • Communicate with the Reporting Party as necessary to clarify technical details,

  • Validate the vulnerability and initiate appropriate remediation measures and

  • Address confirmed vulnerabilities in a timely manner, taking into account severity, impact, and exploitability.

If a reported vulnerability is caused by a third party component integrated into a product, Gira may coordinate with the relevant supplier while maintaining appropriate confidentiality.

8. Coordinated disclosure and publication

Gira supports coordinated disclosure and requests that public disclosure of vulnerability details be coordinated to reduce risks to users and customers.

Information about resolved vulnerabilities may be communicated through updated product information or equivalent product related communication channels.

Gira does not publish separate security advisories or vulnerability identifiers.

9. Safe harbour (non retaliation)

Provided that Reporting Parties comply with this policy and act in good faith, Gira will not initiate legal action against them for activities related to the discovery and reporting of security vulnerabilities.

This safe harbour does not apply to actions that:

  • violate applicable laws or regulations,

  • cause harm to Gira, its customers, or third parties,

  • compromise personal data or privacy or

  • involve premature or uncoordinated public disclosure.

10. Data protection and confidentiality

Reporting Parties are requested to exclude personal data or sensitive customer information unless strictly necessary and to minimize such data wherever possible.

Subject to applicable legal obligations Gira will handle vulnerability information confidentially and use it exclusively for vulnerability management, remediation, compliance and product security improvement.

11. Contact

For vulnerability reports and questions regarding this policy:

Email: psirt@gira.de

Secure web form: https://partner.gira.com/cybersecurity

OpenPGP key: https://www.gira.de/.well-known/psirt-public.asc