Secure Vulnerability Reporting
Have you discovered a security vulnerability in one of DARZ GmbH’s products or services? Please let us know directly. Responsible vulnerability management is an important part of our information security approach.
We carefully review every report we receive and assess it according to a defined process.
A Central Reporting Channel for Security Vulnerabilities
Please use only the address provided below. Reports submitted through Sales, Support tickets, or social media may delay processing and cannot be handled confidentially. Please encrypt your report if it contains details that could be used to exploit the vulnerability.
Not for Service Disruptions or Emergencies
Please report outages, performance issues, or access problems to the IT hotline at +49 6151 8762-333 or support@da-rz.de.
For privacy-related inquiries and reports of personal data breaches, please contact our Data Protection Officer via Contact Form.
What to Report and What Not to Report Here
What to Report and What Not to Report Here
Relevant Reports
Not for This Channel
What a Good Report Contains
Was eine gute Meldung enthält
Affected System
The product, service, URL, or endpoint concerned, along with the version and time of observation, if known.
Reproducible Steps
Steps to reproduce the issue, including the requests used and the observed behavior. Supporting evidence can be provided as an attachment.
Impact Assessment
An assessment of what an attacker could achieve and whether there are any indications that the vulnerability has already been exploited.
How We Handle Your Report
Our coordinated vulnerability disclosure process is part of our Information Security Management System (ISMS) and is aligned with the requirements of ISO/IEC 27001 and the reporting obligations under the Cyber Resilience Act.
Receipt and Acknowledgement
You will receive an acknowledgement of receipt with a tracking number within 24 hours on business days.
Assessment
We verify the report, identify the affected components, and assess the severity. You will normally receive the result within five business days.
Remediation
We develop a fix or risk mitigation measure, inform affected customers, and keep you updated on the progress.
Disclosure
Once a fix is available, we will coordinate the disclosure with you. If you wish, we will acknowledge you by name as the finder. Of course, you may also remain anonymous.
We do not pay rewards for vulnerability reports. We do not operate a bug bounty program.
Step 1: Receipt and Acknowledgement
You will receive an acknowledgement of receipt with a tracking number within 24 hours on business days.
Step 2: Assessment
We verify the report, identify the affected components, and assess the severity. You will normally receive the result within five business days.
Step 3: Remediation
We develop a fix or risk mitigation measure, inform affected customers, and keep you updated on the progress.
Step 4: Disclosure
Once a fix is available, we will coordinate the disclosure with you. If you wish, we will acknowledge you by name as the finder. Of course, you may also remain anonymous.
We do not pay rewards for vulnerability reports. We do not operate a bug bounty program.
Reporting Obligations under Article 14 of the CRA
Regulation (EU) 2024/2847 requires manufacturers of products with digital elements to report actively exploited vulnerabilities and serious security incidents to the competent CSIRT and to ENISA. These obligations have applied since 11 September 2026; the remaining requirements of the Regulation will apply from 11 December 2027. Where DARZ acts as the manufacturer of a product within the meaning of the Regulation, we fulfil these obligations via the designated single reporting platform. The competent national CSIRT for us is the BSI with CERT-Bund.
24 Hours
Early WarningInitial notification after becoming aware of the issue, even if the analysis is not yet complete.
72 Hours
Vulnerability or Incident ReportTechnical description, affected products, and mitigation measures already taken.
14 Days / 1 Month
Final ReportFor vulnerabilities, 14 days after a fix becomes available; for serious incidents, one month after the initial notification.
What This Means for Customers
Distinction Between the Applicable Regulations
The Cyber Resilience Act (CRA) governs the security of products with digital elements and applies to manufacturers. Reports under NIS2 concern significant security incidents affecting the operation of essential services, while reports under Article 33 of the GDPR concern personal data breaches. A single event may trigger multiple reporting obligations. Our process considers all three areas within the same case to ensure that no reporting deadline is missed.
Legal basis:
Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements, in particular Articles 14 and 16.
Framework
Guidelines for Security Researchers
We do not consider a vulnerability report to constitute an attack. If you follow the guidelines below, we will not take legal action against you based on your security research and will treat your report confidentially.
Please Do
Prohibited Activities
This commitment is a voluntary undertaking by DARZ GmbH and does not create any rights or claims against third parties whose systems or data may be affected.Before conducting any security research, please verify that the target system is in fact operated by or belongs to DARZ GmbH.
Frequently Asked Questions
How quickly will I receive a response?
You will receive an acknowledgement within 24 hours on business days. We will normally provide an initial substantive response within five business days. Reports indicating active exploitation will be handled immediately.
Will I be credited as the finder?
Only if you wish to be. We will ask for your consent before any publication and credit you using the name or designation of your choice — or not credit you at all.
Is there a reward?
No. We currently do not operate a bug bounty program and do not pay rewards. This does not affect how we handle your report.
I am a customer and operate my own systems at DARZ. Who is responsible for reporting what?
We are responsible for vulnerabilities in the products and services we provide. For applications that you operate yourself on your own infrastructure, you are responsible for reporting vulnerabilities. Where responsibilities are shared, we will agree on the appropriate course of action on a case-by-case basis. The allocation of responsibilities is specified in your service specification.
Will DARZ also notify me as a customer?
Yes. If a vulnerability or security incident affects the services you receive from us, we will notify you using the contact details specified in your contract. The notification will include information on the impact, risk, and recommended action. Please ensure that your contact details are kept up to date.
How are vulnerabilities in third-party software handled?
If a report concerns a third-party component, we will forward it to the relevant reporting channel and support the coordination process. We will keep you informed of the progress.
Do you accept anonymous reports?
Yes. We handle anonymous reports in the same way. However, without a means of contacting you, we cannot ask follow-up questions or notify you when the case has been closed, which may make the investigation more difficult.
When in Doubt, Report It
It is better to receive one report too many than to miss a vulnerability. We review every report and provide feedback, even if the suspected vulnerability is not confirmed.
Security Reports
cra@da-rz.de
Service Disruptions & Support
Address
DARZ GmbH
Julius-Reiber-Straße 11
64293 Darmstadt



