Vulnerability Disclosure Policy
Coordinated Vulnerability Disclosure (CVD) Policy
Version: 1.0
Last updated: 20.08.2026
1. Purpose of the Policy
EasternGraphics GmbH (“EasternGraphics”) is committed to ensuring the security of its products, services, systems and the data entrusted to it. Through this Policy, EasternGraphics provides a clear, responsible and transparent process through which external security experts, customers, partners and other third parties can report potential security vulnerabilities.
The aim of this Policy is to:
- identify, assess and rectify security vulnerabilities at an early stage;
- provide a reliable channel of communication for security reports;
- facilitate the coordinated and responsible disclosure of security vulnerabilities;
- minimize risks to customers, partners, users and EasternGraphics; and
- ensure that the handling of security vulnerability reports is transparent and efficient.
2. Scope
This Policy applies to potential security vulnerabilities in all products, services and systems developed, operated, provided or otherwise under the responsibility of EasternGraphics, where and to the extent that EasternGraphics has technical or organizational control over them.
These include the following products, services and systems provided by EasternGraphics:
- websites and web applications;
- cloud, SaaS and other online services;
- APIs, interfaces and integrations;
- desktop, client and mobile applications;
- customer, partner, administration and support portals;
- backend systems, authentication services and account management services;
- EasternGraphics domains and subdomains, as well as product- or service-related domains through which EasternGraphics products or services are provided, including, in particular, domains under *.easterngraphics.com and *.pcon-solutions.com; and
- any products, services, systems, applications and domains introduced in the future, insofar as they are developed, operated or otherwise under the responsibility of EasternGraphics.
3. Out of Scope
In particular, this Policy does not apply to:
- products, services, systems or infrastructure that are not operated, developed or otherwise under the responsibility of EasternGraphics;
- third-party products, services, systems or infrastructure;
- security vulnerabilities resulting from or related to customer- or user-side configurations, infrastructure or integrations;
- social engineering attacks targeting employees, customers, partners or other third parties;
- phishing, vishing, pretexting or similar attacks targeting individuals;
- physical attacks on buildings, hardware or end-user devices;
- denial-of-service (DoS/DDoS) testing, load testing or other activities that may impair availability;
- automated mass submissions without specific validation in relation to EasternGraphics products or services;
- reports that do not demonstrate a plausible security impact or lack sufficient technical substance; and
- spam, SEO, trademark or other matters unrelated to security.
4. Contact for Security Reports
EasternGraphics provides two dedicated contact addresses for security reports to ensure that reported issues can be assigned to the appropriate team as efficiently as possible.
4.1 Product Security Vulnerabilities – PSIRT
Please use psirt@easterngraphics.com if your report relates to a security vulnerability in a product, software, application, cloud/SaaS product, API or product feature provided by EasternGraphics.
This includes security vulnerabilities in the following, as provided by EasternGraphics:
- desktop, client or mobile applications;
- cloud or SaaS products;
- product backends and product-related APIs;
- product features, authentication mechanisms or product-related integrations; and
- other product components developed by or otherwise under the responsibility of EasternGraphics.
PGP for PSIRT
Download Public Key
4.2 Security Vulnerabilities in Infrastructure and Services – CSIRT
Please use csirt@easterngraphics.com if your report relates to a security vulnerability in EasternGraphics’ corporate, web, portal or service infrastructure, in particular:
- EasternGraphics’ websites and web presences;
- support, customer or partner portals;
- login, account, administration or backend services;
- publicly accessible servers, web applications or infrastructure components; and
- misconfigurations or security vulnerabilities in online services operated by EasternGraphics, insofar as they cannot clearly be attributed to a specific product.
PGP for CSIRT
Download Public Key
4.3 If You Are Unsure Which Contact Is Appropriate
If you are unsure which contact address is appropriate, please send your report to psirt@easterngraphics.com or csirt@easterngraphics.com. EasternGraphics will forward the report internally to the appropriate team.
4.4 Contents of a Report
Please include the following information in your report:
- a clear description of the security vulnerability;
- the affected product and product version, service, URL, API or component;
- steps to reproduce the vulnerability;
- the suspected or observed impact;
- a proof of concept, screenshots, log excerpts or sample requests, where necessary;
- the time, test environment and prerequisites; and
- your name or a pseudonym, as well as contact details for any follow-up questions.
Please provide only the information necessary to investigate and remediate the security vulnerability and avoid unnecessarily disclosing personal, confidential or other sensitive data.
5. Security Research Rules and Expectations
EasternGraphics welcomes security research provided that it is conducted responsibly, proportionately and with due regard for users, systems and data.
EasternGraphics asks individuals reporting security vulnerabilities to, in particular:
- act in good faith and conduct only those activities necessary to identify, verify and document a security vulnerability;
- not modify, delete or disclose any data without authorization;
- not download, exfiltrate or otherwise process any third-party data, except to the extent technically unavoidable and necessary to demonstrate the security vulnerability;
- not conduct availability attacks or load, brute-force or fuzzing tests against production systems;
- not conduct social engineering or phishing attacks against employees, customers or partners;
- not establish persistence in systems, install backdoors or escalate privileges beyond what is necessary to demonstrate the security vulnerability;
- allow EasternGraphics sufficient time to investigate and remediate the security vulnerability before disclosing any details;
- treat information concerning the security vulnerability as confidential until coordinated disclosure has been agreed upon or EasternGraphics has consented to its publication;
- not publicly disclose any security vulnerability before EasternGraphics has had an opportunity to investigate the report and take appropriate remedial measures;
- not unnecessarily collect, store or disclose personal data, trade secrets or confidential information of third parties;
- notify EasternGraphics without undue delay if you encounter personal data or sensitive information during your investigation; and
- immediately cease testing if it jeopardizes the availability, integrity or confidentiality of customer data or production systems.
6. EasternGraphics Commitments / Safe Harbor
If you act in good faith, in accordance with this Policy and within the bounds of applicable law, EasternGraphics will endeavor to:
- review your report in good faith and in a timely manner;
- cooperate with you to an appropriate extent in relation to the security vulnerability you have reported;
- not take legal action against you solely on the basis of security research and reporting permitted under this Policy; and
- contact you if there are any questions or if additional information is required.
This commitment applies, in particular, only to the extent that:
- no intentional harm is caused;
- no data is misused, stored, modified or disclosed;
- availability is not impaired; and
- no laws, contractual obligations or third-party rights are adversely affected or violated.
This Policy does not constitute a waiver of any statutory rights or a general authorization to test systems outside the scope described herein.
7. Handling Process
EasternGraphics follows a structured, risk-based CVD process when handling security reports.
7.1 Acknowledgement of Receipt
EasternGraphics generally acknowledges receipt of a security report within 7 calendar days.
7.2 Initial Review and Triage
Upon receipt, the report is reviewed for completeness, whether it falls within EasternGraphics’ area of responsibility, plausibility and potential security relevance. If necessary, EasternGraphics will request additional information.
7.3 Validation and Assessment
Reports deemed plausible are technically validated, assessed in terms of exploitability, potential impact, affected products or services, potential impact on customers and required remedial measures, and prioritized accordingly.
7.4 Initial Substantive Response
EasternGraphics will endeavor to provide the reporting party, within 14 calendar days of receipt of the report, with an update on the status of the review, further handling of the report, or any need for additional information.
7.5 Status Updates
For confirmed reports that are being further processed, EasternGraphics informs the reporting party of any material changes in status, if questions arise, or in connection with the coordination of a disclosure.
7.6 Prioritization and Remediation
Confirmed security vulnerabilities are prioritized based on risk, severity, exploitability, affected systems, potential impact on the application, regulatory requirements and technical complexity, and are addressed in accordance with internal processes.
7.7 Coordinated Disclosure
EasternGraphics aims to achieve coordinated disclosure. As a general rule, details of a security vulnerability should only be disclosed once:
- a remediation is available;
- appropriate protective measures have been implemented; or
- EasternGraphics and the reporting party have agreed on an appropriate time for disclosure.
8. Disclosure Timeframes
EasternGraphics aims to assess reported security vulnerabilities as quickly as possible and, depending on their severity, complexity and dependencies, to remediate them.
Unless otherwise agreed on a case-by-case basis, the following general principle applies:
- no disclosure before 90 days have elapsed from the date on which the report was confirmed, unless EasternGraphics expressly agrees to earlier disclosure or specific circumstances require a different, mutually agreed approach.
In justified cases, such as where remediation is complex, there are dependencies on third-party providers, or coordinated customer communications are required, a longer timeframe may be necessary. In such cases, EasternGraphics will endeavor to communicate transparently with the reporting party.
9. No Compensation / No Bug Bounty Program
Unless expressly stated otherwise in a published notice, EasternGraphics does not operate a bug bounty program. Reporting a security vulnerability therefore does not give rise to any entitlement to compensation, reimbursement of expenses or any other benefit.
EasternGraphics nevertheless reserves the right, on a case-by-case basis, to voluntarily recognize reporting parties where appropriate and legally permissible.
10. Handling of Personal Data and Confidential Information
When submitting a security report, please provide only the information necessary to investigate and remediate the security vulnerability.
If your report contains personal data, EasternGraphics will process such data solely for the purpose of handling the security report and in accordance with applicable data protection requirements.
Please do not submit any unnecessary personal data or other confidential information.
11. Exclusion of Abusive Reports
EasternGraphics reserves the right not to process reports further, particularly where they:
- are manifestly abusive or unlawful;
- do not contain sufficient information;
- are based on unauthorized testing methods;
- contain mass-generated, non-specific or unverified findings; or
- concern sales-, marketing- or support-related matters.
12. Contact
EasternGraphics GmbH
Albert-Einstein-Strasse 1
98693 Ilmenau
Germany
Product Security Vulnerabilities (PSIRT)
psirt@easterngraphics.com
Download PGP Public Key
Security Vulnerabilities in Infrastructure and Services (CSIRT)
csirt@easterngraphics.com
Download PGP Public Key
13. Publication of Security-Related Information
EasternGraphics may, at its sole discretion, publish security-related information, information concerning affected products or services, remedial measures, security advisories, or other information relating to reported security vulnerabilities, where appropriate, necessary or expedient.
14. Changes to this Policy
EasternGraphics may amend this Policy at any time with effect for the future, in particular to reflect technical, organizational or legal developments. The version published at the following address at the relevant time shall prevail:
https://www.easterngraphics.com/security/vulnerability-disclosure-policy