Cyber Resilience Act
The security of our intralogistics systems, our software, and our remote maintenance services is a top priority for us. If you have discovered a vulnerability in one of our products or observe a security incident affecting a system we have supplied, our software, or our remote maintenance services, please report it to us. This page serves as our central point of contact for security reports regarding our products and services.
1. How to Contact Us
- Email: cra@hoermann-logistik.de.
In the event of an ongoing attack or an actively exploited vulnerability, please mark your report as urgent or call us at:
- Phone: +49 (89) 149898 - 79.
2. Information that helps us process your report
Please provide us with the affected product or system (if known), the software and its version, a description of the vulnerability or the observed behavior, the steps required to reproduce the behavior, the date and time, and a way to contact you for follow-up questions. You may also submit a report anonymously; however, in that case, we will not be able to provide you with any feedback.
3. What Happens After You Submit a Report
We will confirm receipt of your report within 24 hours. We will evaluate the report, keep you updated on the status of the investigation, and notify you when a fix is available. We will immediately inform affected customers about emergency measures and security updates. Where we are legally required to do so, we report vulnerabilities and security incidents to the relevant authorities; we will not disclose your personal data in this process unless you consent to it.
4. Coordinated Disclosure of Vulnerabilities
We follow the principle of coordinated disclosure. For us, this means: We treat your report confidentially, work with you to resolve the issue, and, once a security update is available, publish a security advisory that includes a description, affected versions, severity level, and workaround.
5. Security Advisories
Here we publish information about resolved vulnerabilities in our products:
- List of security advisories (currently no entries).
Customers with a maintenance contract also receive security advisories directly from their designated security contact.
6. Legal Notice
This contact point is intended for reporting vulnerabilities and security incidents to us as the manufacturer and service provider and serves as our central point of contact in accordance with Regulation (EU) 2024/2847 (Cyber Resilience Act). Reporting an incident to us does not replace any reporting obligations you may have as an operator or organization under the BSI Act.