Cyber Security at manroland Goss
Discovered a vulnerability?
The security of our products is of very high importance to manroland Goss.
If you have discovered a potential vulnerability, we encourage you to report it to us responsibly and privately.
product-security@manrolandgoss.com
Encrypted communication: Download PGP/GPG Public Key
Fingerprint: E6579A8AC4D163C2FB75813223B64AA5FBB86D72
What should your report include?
To enable us to review and process your report as quickly as possible, please include the following information:
- A clear description of the issue
- The affected product and version number
- Steps to reproduce
- Proof-of-concept code, logs, screenshots, or videos, if helpful
- Your contact details, if you want a response
- If you believe the issue is actively exploited, please state that in your report
Our Vulnerability Disclosure Policy
manroland Goss values the security of our products. We encourage security researchers, customers, and any other third parties to report vulnerabilities responsibly so we can investigate and remediate them in a coordinated manner.
Our Vulnerability Disclosure Policy explains how to report vulnerabilities to us, what to expect after reporting, and what testing activities are permitted.
What happens after you submit a report?
01 – Acknowledgement of receipt
Within 1 business day
02 – Initial assessment
Within 3 business days
03 – Status update
As needed, especially if remediation takes longer
04 – Coordinated disclosure
Agreement on further measures
We handle reports in accordance with our Vulnerability Disclosure Policy. We will not initiate legal action against individuals who act in good faith, with reasonable care, and in compliance with this policy.
We do not operate a bug bounty programme and do not offer monetary compensation for vulnerability reports.
Further security information
Our standardised security information can be found in our security.txt file.