Report a Security Vulnerability

EasternGraphics GmbH takes the security of its products, services, and systems seriously. If you have discovered a potential security vulnerability in any product, service, or system developed, operated, or controlled by EasternGraphics GmbH, we ask you to report it responsibly.

Scope

This policy applies to security vulnerabilities in all products, services, and systems developed, operated, provided, or otherwise controlled by EasternGraphics GmbH, to the extent EasternGraphics GmbH has technical or organizational responsibility for them. This includes, in particular, products, software, cloud and online services, APIs, websites, web applications, portals, and EasternGraphics GmbH domains and subdomains, including in particular *.easterngraphics.com and *.pcon-solutions.com.

Out of scope are, in particular, third-party systems not operated or controlled by EasternGraphics GmbH, social engineering, DoS/DDoS testing, and purely non-security-related reports.

Vulnerability Reporting via Online Form

Use our online form to report the discovered vulnerability to us in a structured manner, including all necessary information. The form also allows you to submit your report anonymously. 

Vulnerability Reporting via Email

Which contact address should I use?

Product vulnerabilities (PSIRT)

Please use psirt@easterngraphics.com if your report concerns a vulnerability in an EasternGraphics GmbH product, software application, cloud/SaaS offering, API, or product-related feature.

Download PGP Public Key for PSIRT

Infrastructure and service vulnerabilities (CSIRT)

Please use csirt@easterngraphics.com if your report concerns a vulnerability in EasternGraphics GmbH web, portal, service, or corporate infrastructure, such as websites, web portals, login services, servers, or general online infrastructure.

Download PGP Public Key for CSIRT

If you are unsure

If you are unsure which address is appropriate, please send your report to psirt@easterngraphics.com or csirt@easterngraphics.com. EasternGraphics GmbH will route the report internally to the appropriate team.

What should a report contain?

Please include as much of the following information as possible:

  • affected product, service, URL, API, component, or product version
  • description of the vulnerability
  • steps to reproduce the issue
  • observed or potential impact
  • proof of concept, screenshots, logs, or sample requests where necessary
  • your name or pseudonym and a way to contact you for follow-up questions

Please include only information necessary for review and remediation.

Handling Process

EasternGraphics GmbH follows a structured handling process for security reports.

  • acknowledgement of receipt: generally within 7 calendar days
  • initial qualified response: generally within 14 calendar days
  • status communication: at reasonable intervals for confirmed and actively handled reports
  • coordinated disclosure: generally only after a fix or appropriate mitigation is available

Disclosure Principle

EasternGraphics GmbH aims for coordinated disclosure. Unless otherwise agreed on a case-by-case basis, the general principle is:

  • no public disclosure before 90 days after confirmation of the reported vulnerability, unless EasternGraphics GmbH expressly agrees to earlier disclosure or special circumstances require a different coordinated approach.

Safe Harbor

If you act in good faith, in accordance with this policy, and within the limits of applicable law, EasternGraphics GmbH will make reasonable efforts to review your report in a timely manner, work with you as appropriate, and refrain from initiating legal action against you solely for reporting a vulnerability in accordance with this policy.

Full Policy

Contact

Product vulnerabilities (PSIRT)
psirt@easterngraphics.com

Infrastructure and service vulnerabilities (CSIRT)
csirt@easterngraphics.com

EasternGraphics GmbH
Albert-Einstein-Straße 1
98693 Ilmenau
Germany