Reporting Security Vulnerabilities
We take immediate action when security vulnerabilities are found in our products. Anyone who discovers a vulnerability in a BR Technologies device should report it to security@br-tech.de. A PGP key is available for confidential messages (https://www.br-tech.de/.well-known/pgp-key.txt).
What We Promise
We will acknowledge your report within three workingdays. Within ten days, we will provide our initial assessment and keep you informed of our progress. We will discuss any public disclosure with you. Anyone who follows the rules will not face legal repercussions.
What We Ask of You
Describe the issue in detail, but do not access third-party data. Do not modify or delete anything, and do not interrupt any processes. Please give us sufficient time to resolve the issue before considering a public disclosure.
Please direct inquiries regarding malfunctions, functional errors, or replacement parts to our service department.
Legal Assurance (Safe Harbor)
If you comply with the rules described above, we consider your research to be authorized by us. Specifically, this means:
We will not file a criminal complaint or report you to the prosecuting authorities.
We will not assert any civil claims against you, whether for injunctive relief or for damages.
Should an authority or a third party nevertheless take action against you, we will confirm to you in writing, upon request, that you acted with our consent.
This assurance applies to us alone. We cannot make any commitment regarding third-party systems, data or rights, and law enforcement authorities may act independently of us. If you are unsure whether a planned test is still covered by this policy, please ask us in advance at security@br-tech.de.