Cyber Security at manroland Goss

Discovered a vulnerability?

The security of our products is of very high importance to manroland Goss.

If you have discovered a potential vulnerability, we encourage you to report it to us responsibly and privately.

REPORT A VULNERABILITY

Encrypted communication: Download PGP/GPG Public Key
Fingerprint: E6579A8AC4D163C2FB75813223B64AA5FBB86D72

What should your report include?

To enable us to review and process your report as quickly as possible, please include the following information:

  • A clear description of the issue
  • The affected product and version number
  • Steps to reproduce
  • Proof-of-concept code, logs, screenshots, or videos, if helpful
  • Your contact details, if you want a response
  • If you believe the issue is actively exploited, please state that in your report

Our Vulnerability Disclosure Policy

manroland Goss values the security of our products. We encourage security researchers, customers, and any other third parties to report vulnerabilities responsibly so we can investigate and remediate them in a coordinated manner.

Our Vulnerability Disclosure Policy explains how to report vulnerabilities to us, what to expect after reporting, and what testing activities are permitted.

DOWNLOAD VULNERABILITY DISCLOSURE POLICY (PDF)

What happens after you submit a report?

01 – Acknowledgement of receipt
Within 1 business day

02 – Initial assessment
Within 3 business days

03 – Status update
As needed, especially if remediation takes longer

04 – Coordinated disclosure
Agreement on further measures

We handle reports in accordance with our Vulnerability Disclosure Policy. We will not initiate legal action against individuals who act in good faith, with reasonable care, and in compliance with this policy.

We do not operate a bug bounty programme and do not offer monetary compensation for vulnerability reports.

Further security information

Our standardised security information can be found in our security.txt file.

VIEW SECURITY.TXT