Kraft Group PSIRT – Product Security Incident Response Team

The security of our products is a top priority for us. Despite careful development and regular testing, vulnerabilities can never be completely ruled out. That is why we rely on open communication with security researchers, customers, and partners: Anyone who discovers a potential vulnerability in one of our products can report it to us through our Product Security Incident Response Team (PSIRT).

Our team reviews and evaluates every report we receive and, if necessary, takes appropriate measures to address the issue. We treat all reports confidentially and adhere to the principles of Coordinated Vulnerability Disclosure described below. This ensures that vulnerabilities are handled responsibly before details are made public and that our customers remain reliably informed.

Reporting Vulnerabilities

If you suspect that you have discovered a security vulnerability in a Kraft Group product, please report it using the contact form or by email.

Please include the following information in your email:

  • Name of the person submitting the report
  • Contact details: email address and phone number
  • Name of the organization
  • Name of the affected system
  • Affected component, software or firmware version
  • Type of vulnerability (e.g., XSS, buffer overflow, hard-coded credentials, CWE ID, CVE ID if available …)

What Happens to Your Report?

The Kraft Group ensures that the information is sent to a limited group of designated Kraft Group employees—the Kraft Group Product Security Incident Response Team (PSIRT). Neither unauthorized employees nor external users have access to the information you submit.

The Kraft Group also ensures that the security researcher’s identity and contact information are kept confidential. The Kraft Group PSIRT will investigate the reported vulnerability and contact you as soon as possible.

Contact Form for Reporting Vulnerabilities



Contact:


Kraft Group
Speckenstraße 6
33397 Rietberg

E-Mail:

Kraft Group PSIRT Public Key
You can download our PGP key here
Fingerprint: 36DF 3E7A 9202 EC92 958F B679 CC78 7E5D 3A39 4745
Language: German or English
Encryption: optional, but recommended

Type of vulnerability (e.g., XSS, buffer overflow, hard-coded credentials, CWE-ID, CVE-ID if available…)
* Required fields

Reported Vulnerabilities

2026-09-03_Placeholder-Vulnerability

To date, no critical security vulnerabilities have been identified in our products. Once a vulnerability has been confirmed and resolved, we will publish the corresponding security advisory here.