Skip to main navigation Skip to main content Skip to page footer

Security of our products and solutions

The increasing connectivity of machines, systems and digital solutions also creates new requirements for IT and product security. KASTO therefore takes the security of its products and solutions very seriously.

The KASTO Product Security Incident Response Team (PSIRT) is the central point of contact for reports of potential security vulnerabilities and security incidents relating to our products, machines, systems, software and digital services.

Our aim is to identify potential vulnerabilities at an early stage, assess them and initiate appropriate measures. We therefore expressly encourage security experts, independent security researchers, customers, partners and other individuals to report potential security issues to us.

Early and coordinated reporting enables us to assess matters jointly, coordinate the necessary measures and continuously improve the security of our products and solutions.

How can you report a security vulnerability to KASTO?

If you have identified a potential security vulnerability in a KASTO product, machine, system, software application or one of our digital services, please contact our PSIRT.

Reports may be submitted in German or English.

PSIRT contact:
cra(at)kasto.com

What information should a report contain?

To enable us to understand and assess a reported security vulnerability as quickly as possible, your report should, where possible, include the following information:

  1. Name of the person submitting the report
  2. Contact details, in particular an email address
  3. Company or organisation
  4. Name of the affected KASTO product or system
  5. Product, software or firmware version, if known
  6. Description of the identified security vulnerability and its potential impact
  7. Description of the conditions and steps required to reproduce the vulnerability
  8. Information on whether the vulnerability has already been published or reported elsewhere

Please do not send us exploit programs or other malicious files unless requested to do so. A description of the vulnerability and how it can be reproduced that is as precise as possible will support our analysis.

Processing security reports

Upon receipt of a report, the KASTO PSIRT reviews the information provided and assesses its potential security relevance.

Depending on the type, scope and complexity of the reported vulnerability, the investigation may take varying amounts of time. If further information is required for the assessment, we will contact the person who submitted the report.

Once the analysis has been completed, we decide on the necessary measures. These may include, for example, technical modifications, software or firmware updates, configuration changes or additional protective measures.

In the case of security-relevant vulnerabilities, we inform affected customers and users in an appropriate manner about the issue and the recommended measures.

 

Coordinated disclosure

KASTO generally follows a coordinated approach when handling security vulnerabilities.

The aim is to allow sufficient time for technical analysis and the development of appropriate measures before information about a vulnerability is made public. This helps to minimise risks to our customers, users and third parties.

Where disclosure is necessary or appropriate, KASTO will provide the relevant information in a suitable form.

 

Security Advisories

For confirmed and security-relevant vulnerabilities, KASTO may publish Security Advisories.

A Security Advisory provides information about an identified security vulnerability and may include, where relevant, for example:

  • a description of the vulnerability,
  • an assessment of the potential impact and severity,
  • affected products and versions,
  • information on whether and how products are affected,
  • recommended protective and remedial measures,
  • available updates or fixes, and
  • where applicable, acknowledgement of the person or organisation that reported the vulnerability.

Our shared goal: secure products

Product security is a continuous process for KASTO. Reports from security researchers, customers, partners and other stakeholders make an important contribution to identifying potential vulnerabilities at an early stage and further improving the security of our products and solutions.

We therefore appreciate responsible and coordinated reporting of security issues.

Contact KASTO PSIRT Now