Reporting Vulnerabilities and Incidents to SAFELOG
The security of our products, information, IT infrastructure, and business processes is a top priority for SAFELOG. Our Security Team is the central point of contact for reporting security issues to SAFELOG, whether they involve a vulnerability in a SAFELOG product, a security incident, or any other security-related concern.
SAFELOG Handling Process
1. Report a Security Issue to SAFELOG
If you have discovered a potential vulnerability or incident, please report it to SAFELOG. We will acknowledge receipt within five business days (Location: Munich, Germany).
Please never send sensitive information, such as passwords, login credentials, or information requiring special protection, in unencrypted form. If such information is required for further processing, we will coordinate a suitable secure transmission method with you.
E-Mail: security@safelog.de
Please note that only reports submitted in English or German can be processed.
Please provide us with the following information where possible:
- type and description of the vulnerability/incident
- date or time period of the determination
- affected infrastructure, applications, information, business processes, or products (name and serial number)
- potential impact
- application/product configuration
- software/firmware version
- description of the operating environment
- evidence, such as network logs, screenshots, or error messages
- vulnerability type (CWE category)
- steps to reproduce
- proof-of-concept
- wether the vulnerability/incident has already been publicly disclosed
- your contact information in case of follow-up questions, unless you wish to submit an anonymous report
2. Triage and Analysis
SAFELOG investigates the vulnerability or the incident and attempts to reproduce the security issue. The SAFELOG Security Team works closely with the relevant development teams throughout this process. At the same time, there is regular communication with the reporter of the issue. Depending on the nature, severity, and impact of the issue, the CERTs of affected customers, the relevant CERTs, and legally mandated reporting agencies are also involved as necessary. Legally required reports are submitted within the applicable timeframe.
3. Remediation
Based on the analysis, a determination is made whether mitigations or fixes are required to resolve the issue. These are developed, tested, and prepared for distribution. Whenever possible, the SAFELOG Security Team works with the reporter to confirm the effectiveness of the corrective measure. SAFELOG aims to resolve reported vulnerabilities within 90 days. SAFELOG aims to resolve reported vulnerabilities within 90 days. Depending on the severity, exploitability, and complexity, SAFELOG resolves reported product vulnerabilities as quickly as possible. However, the resolution time may vary. Separate incident response, escalation, and reporting processes apply to security incidents.
4. Disclosure
SAFELOG notifies affected customers directly about available patches. In addition, security advisories are published on this page. A security advisory typically contains the following information:
- description of the vulnerability, including the CVE reference and CVSS score
- information for identification of known affected products and software/hardware versions
- information on workarounds and mitigating measures
- availability of workarounds and fixes
- acknowledgment of the discoverer by name, subject to their consent
Policy on Responsible Disclosure
The security of our products throughout their entire lifecycle is an integral part of our commitment to quality. The SAFELOG Security Team serves as the central coordinating point for all matters related to vulnerability reports and remediation.
When a vulnerability is reported, the Security Team coordinates with our development teams to assess and address the vulnerability, keeping the reporter informed throughout the entire process. SAFELOG is committed to coordinated disclosure of vulnerabilities and therefore asks reporters to treat reported issues as confidential until a fix is available.
Security reports are always welcome, regardless of whether you are a customer, partner, security researcher, or CERT, and regardless of existing contracts or the product lifecycle. Anonymous reports are welcome. We commit to addressing any vulnerability that is related to SAFELOG products.
Commitments from SAFELOG
We ask that you refrain from publicly disclosing vulnerabilities and incidents or sharing them with third parties until a fix is provided.
SAFELOG commits to:
- acknowledge receipt of the vulnerability or incident report within five business days
- resolve the reported vulnerability or incident, typically within 90 days (for details see: 3. Remediation)
- regularly update the reporter on the status of the issue
- notify the reporter as soon as the security issue has been resolved
SAFELOG will treat the reported information as confidential and make it accessible only to authorized persons. This applies in particular to the reporter’s identity. Legal obligations to report, notify, or provide information remain unaffected hereby.
SAFELOG will not pursue legal action against reporters who submit vulnerability reports, provided that the reporter:
- does not exploit vulnerabilities beyond what is necessary to demonstrate their existence
- will not cause any harm to SAFELOG, our customers, or others
- of the issue does not compromise the privacy or security of our customers or the operation of our services
- is not violating any criminal law provisions
- will not disclose details about the vulnerability or incident until SAFELOG has confirmed that the vulnerability has been fully resolved
Security Advisories
Information about security vulnerabilities affecting SAFELOG products.
| SAFELOG ID | Title | CVSS Score | Affected Products | Publication date / Last Update | Downloads |
| There are currently no security advisories available. | |||||
SAFELOG would like to thank all security researchers who contribute to the security of SAFELOG and our products.
