- SECURITY REPORTING · CYBER RESILIENCE ACT
- SECURITY REPORTING · CYBER RESILIENCE ACT
Incident & Vulnerability Reporting
The safety and security of our customers is the highest priority for Trench Group.
Even though we apply the best security measures available to us, vulnerabilities in our products, services, or systems can never be fully excluded. If you have identified such a vulnerability, we encourage you to report it to us so that we can address it promptly.
- Reporting process
How to Report
- The date and time of discovery
- The affected product, including product model and product number, together with every software version number known to you
- A detailed description of the vulnerability, covering, for example, the tools used, the target, the steps performed, and the results obtained, along with the artefacts used during discovery
- A proposed correction of the vulnerability, if available
- Submit a report
Report a Vulnerability or Security Incident
This single form is shared across all Trench Group products and reporting channels – handled by our Product Security Incident Response Team (PSIRT).
- Please observe
Rules when Investigating & Reporting
- Refrain from accessing any data, whether personal or non-personal, that is not explicitly assigned to you or for which you have not obtained prior consent.
- Do not engage in any activity involving the product that could cause harm to yourself or to others, or that could lead to potentially dangerous situations.
- What to expect
Acknowledgement & Response
We aim to provide a first acknowledgement of your report within five business days and to complete our internal analysis within ten business days. All correspondence regarding your report will be sent from psirt@trench-group.com.
Should we require additional information, we will contact you. We will also keep you informed about the status of the reported vulnerability.
Please note that the timelines stated above cannot be guaranteed. Our security team will nevertheless make every effort to keep you informed about the progress of any vulnerability you have reported.
- Public disclosure
Previously Reported Vulnerabilities
|
Product
|
Vulnerability
|
Reported
|
Status
|
|---|---|---|---|
|
product name
|
type of vulnerability
|
date (dd.mm.yyyy)
|
RESOLVED
|
- Legal basis
Data Privacy
Legal basis for processing
The processing of personal data received through this vulnerability disclosure channel is based on Art. 14 of Regulation (EU) 2024/2847 (Cyber Resilience Act), which obliges manufacturers to report actively exploited vulnerabilities and severe security incidents to the relevant authorities.
The responsible vulnerability handling team may process the following data, where provided:
- the identity, function, and contact details of the reporter;
- the reported information, facts, and evidence;
- the actions taken to process the report.
Disclosure of data
Retention
Retention periods depend on the outcome of the investigation and may differ according to local legal requirements. Where:
- the report is unsubstantiated, all data collected is deleted from our systems in due course;
- the report is substantiated, all data collected is deleted in due course in accordance with applicable law, once verification of the reported facts has been completed or once the data is no longer relevant.