Statement on the procedure for reporting security vulnerabilities.
Owner: Hettich Marketing- und Vertriebs GmbH & Co. KG
Version / Effective from: 1.0 / 11.09.2026
1. Scope
This policy applies to products with digital components manufactured by Hettich companies, including their firmware, software and configuration programmes.
2. Reporting procedure
Please report suspected vulnerabilities and security incidents via our reporting form.
3. Content of a report
Please provide the following information wherever possible:
- Affected product and version
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Proof of concept, screenshots or log files (if available)
- Your contact details for follow-up enquiries
Reports may also be submitted anonymously. We will accept reports even if you are unable to use encrypted channels.
4. Processing and communication
We will confirm receipt of your report within 7 working days. We will inform you of the outcome of our investigation and whether the reported vulnerability has been confirmed. We will remain in contact with you until the process is complete and keep you informed of the status of the investigation. If you would like to receive feedback on your report, please provide your contact details.
5. Coordinated disclosure and security advisory
We promise to:
- carefully review every report
- treat reporting parties with respect and professionalism
- prioritise vulnerabilities according to risk
- aim for coordinated disclosure
- maintain the confidentiality of the report while it is in progress





