Cyber Resilience Act

Secure Vulnerability Reporting

Have you discovered a security vulnerability in one of DARZ GmbH’s products or services? Please let us know directly. Responsible vulnerability management is an important part of our information security approach.

We carefully review every report we receive and assess it according to a defined process.

Full rack Colocation

A Central Reporting Channel for Security Vulnerabilities

Please use only the address provided below. Reports submitted through Sales, Support tickets, or social media may delay processing and cannot be handled confidentially. Please encrypt your report if it contains details that could be used to exploit the vulnerability.

Availability 24/7, processing on business days
Languages German, English
Acknowledgement Within 24 hours on business days
Anonymous reports Accepted – however, we cannot provide feedback in this case

Not for Service Disruptions or Emergencies

Please report outages, performance issues, or access problems to the IT hotline at +49 6151 8762-333 or  support@da-rz.de.
For privacy-related inquiries and reports of personal data breaches, please contact our Data Protection Officer via Contact Form.

What to Report and What Not to Report Here

What to Report and What Not to Report Here

Relevant Reports

Vulnerabilities in DARZ GmbH services, portals, and applications
Vulnerabilities in products with digital elements provided by DARZ.
Evidence of active exploitation of a known vulnerability
Misconfigurations affecting confidentiality or availability
Exposed credentials, keys, or certificates related to DARZ
Anomalies in our PKI infrastructure or in certificates we have issued

Not for This Channel

Service disruptions, outages, and support requests related to existing contracts
Results from automated scans without a demonstrated impact
Reports limited to missing security headers or theoretical configuration recommendations
Phishing emails you have received – please report these to Support
Sales inquiries and job applications

What a Good Report Contains

Was eine gute Meldung enthält

Affected System

The product, service, URL, or endpoint concerned, along with the version and time of observation, if known.

Reproducible Steps

Steps to reproduce the issue, including the requests used and the observed behavior. Supporting evidence can be provided as an attachment.

Impact Assessment

An assessment of what an attacker could achieve and whether there are any indications that the vulnerability has already been exploited.

How We Handle Your Report

Our coordinated vulnerability disclosure process is part of our Information Security Management System (ISMS) and is aligned with the requirements of ISO/IEC 27001 and the reporting obligations under the Cyber Resilience Act.

Step 1
Step 1

Receipt and Acknowledgement

You will receive an acknowledgement of receipt with a tracking number within 24 hours on business days.

Step 2
Step 2

Assessment

We verify the report, identify the affected components, and assess the severity. You will normally receive the result within five business days.

Step 3
Step 3

Remediation

We develop a fix or risk mitigation measure, inform affected customers, and keep you updated on the progress.

Step 4
i
Step 4

Disclosure

Once a fix is available, we will coordinate the disclosure with you. If you wish, we will acknowledge you by name as the finder. Of course, you may also remain anonymous.

We do not pay rewards for vulnerability reports. We do not operate a bug bounty program.

Step 1: Receipt and Acknowledgement

You will receive an acknowledgement of receipt with a tracking number within 24 hours on business days.

Step 2: Assessment

We verify the report, identify the affected components, and assess the severity. You will normally receive the result within five business days.

Step 3: Remediation

We develop a fix or risk mitigation measure, inform affected customers, and keep you updated on the progress.

Step 4: Disclosure

Once a fix is available, we will coordinate the disclosure with you. If you wish, we will acknowledge you by name as the finder. Of course, you may also remain anonymous.

We do not pay rewards for vulnerability reports. We do not operate a bug bounty program.

Cyber Resilience Act

Reporting Obligations under Article 14 of the CRA

Regulation (EU) 2024/2847 requires manufacturers of products with digital elements to report actively exploited vulnerabilities and serious security incidents to the competent CSIRT and to ENISA. These obligations have applied since 11 September 2026; the remaining requirements of the Regulation will apply from 11 December 2027. Where DARZ acts as the manufacturer of a product within the meaning of the Regulation, we fulfil these obligations via the designated single reporting platform. The competent national CSIRT for us is the BSI with CERT-Bund.

24 Hours

Early WarningInitial notification after becoming aware of the issue, even if the analysis is not yet complete.

72 Hours

Vulnerability or Incident ReportTechnical description, affected products, and mitigation measures already taken.

14 Days / 1 Month

Final ReportFor vulnerabilities, 14 days after a fix becomes available; for serious incidents, one month after the initial notification.

Trigger Recipients Deadline
Actively exploited vulnerability in a product CSIRT (BSI) and ENISA 24-hour early warning, 72-hour report, final report within 14 days
Serious security incident affecting product security CSIRT (BSI) and ENISA 24-hour early warning, 72-hour report, final report within 1 month
Users affected by a product Customers and, where required, the public Without undue delay after becoming aware of the issue, including recommended actions
External report to DARZ Reporting channel: cra@da-rz.de Acknowledgement within 24 hours on business days

What This Means for Customers

You will be notified as soon as a vulnerability affects the services you use.
The notification will include information on the impact, risk, and recommended actions.
We will specify whether and when a fix will be available.
If your organization has its own reporting obligations under NIS2 or DORA, we will provide the information you need to meet those obligations.

Distinction Between the Applicable Regulations

The Cyber Resilience Act (CRA) governs the security of products with digital elements and applies to manufacturers. Reports under NIS2 concern significant security incidents affecting the operation of essential services, while reports under Article 33 of the GDPR concern personal data breaches. A single event may trigger multiple reporting obligations. Our process considers all three areas within the same case to ensure that no reporting deadline is missed.

Legal basis:
Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements, in particular Articles 14 and 16.

Framework

Guidelines for Security Researchers

We do not consider a vulnerability report to constitute an attack. If you follow the guidelines below, we will not take legal action against you based on your security research and will treat your report confidentially.

Please Do

Limit your activities to the minimum necessary to demonstrate the vulnerability.
Do not access third-party data, and do not copy or modify any data.
Report the vulnerability to us first and allow us reasonable time to implement a fix.
Comply with all applicable laws.

Prohibited Activities

Denial-of-service or load testing of any kind
Social engineering targeting employees, customers, or service providers
Publishing vulnerability details before coordinating disclosure with us
Veröffentlichung von Details vor Abstimmung mit uns
Using any data obtained for purposes other than reporting the vulnerability

This commitment is a voluntary undertaking by DARZ GmbH and does not create any rights or claims against third parties whose systems or data may be affected.Before conducting any security research, please verify that the target system is in fact operated by or belongs to DARZ GmbH.

Frequently Asked Questions

How quickly will I receive a response?

You will receive an acknowledgement within 24 hours on business days. We will normally provide an initial substantive response within five business days. Reports indicating active exploitation will be handled immediately.

Will I be credited as the finder?

Only if you wish to be. We will ask for your consent before any publication and credit you using the name or designation of your choice — or not credit you at all.

Is there a reward?

No. We currently do not operate a bug bounty program and do not pay rewards. This does not affect how we handle your report.

I am a customer and operate my own systems at DARZ. Who is responsible for reporting what?

We are responsible for vulnerabilities in the products and services we provide. For applications that you operate yourself on your own infrastructure, you are responsible for reporting vulnerabilities. Where responsibilities are shared, we will agree on the appropriate course of action on a case-by-case basis. The allocation of responsibilities is specified in your service specification.

Will DARZ also notify me as a customer?

Yes. If a vulnerability or security incident affects the services you receive from us, we will notify you using the contact details specified in your contract. The notification will include information on the impact, risk, and recommended action. Please ensure that your contact details are kept up to date.

How are vulnerabilities in third-party software handled?

If a report concerns a third-party component, we will forward it to the relevant reporting channel and support the coordination process. We will keep you informed of the progress.

Do you accept anonymous reports?

Yes. We handle anonymous reports in the same way. However, without a means of contacting you, we cannot ask follow-up questions or notify you when the case has been closed, which may make the investigation more difficult.

When in Doubt, Report It

It is better to receive one report too many than to miss a vulnerability. We review every report and provide feedback, even if the suspected vulnerability is not confirmed.

Security Reports
cra@da-rz.de

Service Disruptions & Support

+49 6151 8762-333
support@da-rz.de

Address

DARZ GmbH
Julius-Reiber-Straße 11
64293 Darmstadt

Jevgenij Peyss - DARZ GmbH Darmstadt

Jevgenij Peyss

Head of Sales and Business Development