BORA Vertriebs GmbH & Co KG always strives to offer its customers first-class, highly reliable products and services. We do this by checking every security vulnerability that is reported after being discovered by partners, customers or external experts.
This policy applies to all security vulnerabilities that you would like to report to us. We recommend that you read this policy in full and act in accordance with its provisions. This ensures that vulnerabilities are correctly identified and treated as such. BORA Vertriebs GmbH & Co KG appreciates the time and effort taken to report vulnerabilities. However, please note that BORA Lüftungstechnik GmbH does not offer monetary compensation for vulnerability disclosures.
If you think that you have found a security vulnerability, please submit your report using this link or by email and include the following information:
Once you have submitted your report, we will start by triaging and remedying the vulnerability. We aim to respond to reports within 10 working days and work on them within 14 working days. We will keep you updated about our progress. We assess the priority of the remedial measures based on the impact, severity and complexity of the vulnerability. As a token of our appreciation, we will include the names of those who have discovered vulnerabilities on our thank-you page, provided they consent to us doing so.
You must not
You must
This policy has been designed to ensure that those who discover vulnerabilities and follow the guidance are not subject to prosecution.
Please report to us vulnerabilities that you discover in IT systems and web applications belonging to BORA Vertriebs GmbH & Co KG or in products sold by BORA Vertriebs GmbH & Co KG. We will then take prompt action to remedy the vulnerability as quickly as possible.
Please follow these steps to report vulnerabilities: