1. Purpose of this policy
The security of our products and systems is a high priority for us. Our hand-held machines contain software components whose secure operation is important for their use.
If you find a vulnerability in the software of our machines or in our IT systems, we ask you to report it to us responsibly. This policy describes how you can report vulnerabilities and how we handle them.
2. What you can report
In particular, please report:
- Security vulnerabilities in the software of our hand-held machines
- Security issues in our online services
3. How to report a vulnerability (single point of contact)
You can report vulnerabilities to the following central contact address:
Email: security-kst@munsch.de
If possible, please include the following information:
- Serial number and type of the machine
- Software version used (if known; some devices display it at start-up)
- A short technical description of the vulnerability
- Steps to reproduce
- If possible: an assessment of the impact (e.g. data loss, unauthorised access, unexpected machine behaviour)
4. How we handle reports
When you report a vulnerability to us, we will:
- Review your report and classify it internally.
- Send you an acknowledgement of receipt within 5 working days.
- Analyse the vulnerability technically and assess its impact.
- Take appropriate measures (e.g. security update, configuration change, instructions for users).
- Keep you informed about progress and the outcome, where possible.
5. Coordinated vulnerability disclosure
Please do not make vulnerabilities public before we have had the opportunity to review them and develop countermeasures. As part of a coordinated disclosure, we can agree with you:
- whether and when a publication takes place,
- how affected customers are informed,
- whether we credit you as the finder of the vulnerability in a notice (if you wish).
6. What we cannot support
Please note:
- We cannot guarantee rewards (“bug bounties”).
- Activities that lead to data loss, production downtime or damage to customers are not acceptable.
- Please do not perform tests on systems you are not authorised to test (e.g. production systems of customers or third parties).
7. Legal notice
This policy is not an offer and does not establish any claim to a particular response or consideration. We reserve the right to assess reports at our own discretion and to prioritise measures. This policy may be changed at any time; please note the date of the last update.
Last updated: 30.06.2026