Incident & Vulnerability Reporting

The safety and security of our customers is the highest priority for Trench Group.
Even though we apply the best security measures available to us, vulnerabilities in our products, services, or systems can never be fully excluded. If you have identified such a vulnerability, we encourage you to report it to us so that we can address it promptly.

Reports are accepted for evaluation if they relate to websites, services, or products of Trench Group.

How to Report

Please submit your report using the reporting form on this page, in English or German, and include the following information:

Report a Vulnerability or Security Incident

This single form is shared across all Trench Group products and reporting channels – handled by our Product Security Incident Response Team (PSIRT).

Rules when Investigating & Reporting

Acknowledgement & Response

We aim to provide a first acknowledgement of your report within five business days and to complete our internal analysis within ten business days. All correspondence regarding your report will be sent from psirt@trench-group.com.

Should we require additional information, we will contact you. We will also keep you informed about the status of the reported vulnerability.

Please note that the timelines stated above cannot be guaranteed. Our security team will nevertheless make every effort to keep you informed about the progress of any vulnerability you have reported.

Previously Reported Vulnerabilities

In line with our disclosure policy, vulnerabilities that have already been reported and addressed are published below, listed by affected product.
Product
Vulnerability
Reported
Status
product name
type of vulnerability
date (dd.mm.yyyy)
RESOLVED

Data Privacy

All personal data received in connection with a vulnerability report is processed in accordance with our internal data privacy procedures and in compliance with all applicable laws.

Legal basis for processing

The processing of personal data received through this vulnerability disclosure channel is based on Art. 14 of Regulation (EU) 2024/2847 (Cyber Resilience Act), which obliges manufacturers to report actively exploited vulnerabilities and severe security incidents to the relevant authorities.
The responsible vulnerability handling team may process the following data, where provided:

Disclosure of data

Data collected in connection with a vulnerability report is disclosed only to the authorities required under the EU Cyber Resilience Act (e.g. ENISA and the competent national CSIRT). Personal data, such as the reporter’s name and/or e-mail address, is not disclosed to these authorities.

Retention

Retention periods depend on the outcome of the investigation and may differ according to local legal requirements. Where: