Report a vulnerability – Web form
Have you discovered a security vulnerability in a DIAL GmbH product or service? Report it confidentially via the form below – anonymous reporting is expressly permitted.
This form is not intended for general support cases or bugs. For such matters, please use https://www.dialux.com/en-GB/support
Reports that do not concern security-relevant aspects will not be processed.
Reporting guidelines
- Anonymous reporting permitted: The e-mail address is not a mandatory field. Please note that without a contact channel we cannot provide feedback or status updates.
- Confidentiality: We treat every report confidentially. Personal data is disclosed to third parties only with your explicit consent.
- Safe Harbor: We will not initiate legal action against you provided you comply with the conditions of the CVD policy .
- Data protection: Information on the processing of your personal data is available in the privacy information (CVD) .
Alternative: PGP-encrypted e-mail
You may alternatively submit your report PGP-encrypted by e-mail to:
- psirt@dial.de
. The public OpenPGP key is available at
https://security.dial.de/psirt-pgp-key.asc
(Fingerprint:
8C29 895A 9F6B 1A11 7703 BDAD 7AC5 2306 FD2F FCF3). - csirt@dial.de
. The public OpenPGP key is available at
https://security.dial.de/csirt-pgp-key.asc
(Fingerprint:
9B4E DB67 FAAD 0FF8 3D22 3566 67BE ECFF 8B4A 10EE).
What happens to your report
You will receive an automatic acknowledgement of receipt. Within 5 working days you will receive a detailed response; within 10 working days detailed feedback with confirmation or rejection, queries or an explanation of delay. Further details are set forth in the CVD policy .