security@gebhardt-automation.de
Please write in English or German.
Product Security
Our systems protect turbomachinery and process plants. If something about them is vulnerable, we want to know – before someone exploits it. This page is the single point of contact for that.
E-mail is the preferred route. It arrives in a mailbox read by several people.
security@gebhardt-automation.de
Please write in English or German.
For urgent cases – for instance when a vulnerability is already being exploited and a plant in operation is affected.
Our contact details are also published per RFC 9116 at /.well-known/security.txt.
The more precise the details, the faster we can assess and act:
| Acknowledgement of receipt | within 3 working days |
|---|---|
| Initial technical assessment | within 10 working days |
| Publication | as a rule within 90 days of your report, once a remedy is available |
| Credit | if you wish, we name you in the published advisory |
| Cost | security updates for products within their support period are free of charge |
We keep you informed of progress and agree the timing of publication with you. Once a remedy is available we publish an advisory covering the description, severity, affected versions and the route to a fix, and we inform affected users. The standard period for this is 90 days from your report. If a vulnerability is being actively exploited, we act faster. If a remedy in safety technology takes longer – because a certification body has to re-examine it, for instance – we will tell you and name a new date.
If you investigate a vulnerability in good faith and report it to us without disclosing or altering third-party data and without disrupting the operation of a plant, you have nothing to fear from us legally. We regard such research as authorised and will not portray it to third parties as unauthorised access.
This does not cover exfiltration of data, extortion, or interference with plants in operation. Nor can it release us from our obligations towards the authorities: if we learn of an actively exploited vulnerability we have to report it – that report concerns the vulnerability, not your person.
We do not run a bug bounty programme and do not pay rewards. We thank you, credit you by name if you wish, and work with you on the technical side.
The commitments on this page apply to all products with digital elements that we manufacture – the control and protection systems of the BlueLine families including their firmware, as well as our engineering and visualization software. We also accept reports on older systems that are no longer supplied and will tell you what remains technically possible.
Reports about this website itself are welcome and reach us through the same mailbox. They are not product reports and do not lead to an advisory.
If you would rather not write an e-mail, use this form. Name and e-mail address are optional – without an address, though, we cannot reply.
Please do not paste malicious code; file attachments are not possible. If your report needs supporting material, write to security@gebhardt-automation.de.