- About us
- Cyber security
- Security Disclosure Policy
Vulnerability Disclosure Policy Körber Group
Version 1.0 | Public Disclosure Policy
Introduction
Körber is committed to maintaining the security, integrity, and availability of its products, services, systems, and customer data. We welcome responsible security research and encourage the reporting of potential vulnerabilities in accordance with this policy.
1. Purpose
This policy establishes a clear channel for security researchers, customers, partners, and other stakeholders to report security vulnerabilities affecting Körber products, services, websites, and internet-facing systems.
2. Scope
This Policy applies to security vulnerabilities affecting Körber-developed, maintained, or supported products and services, including software, cloud services, APIs, applications, firmware, embedded systems, industrial automation solutions, AI technologies, and other emerging digital solutions offered by Körber. Third-party services and supplier-owned systems are out of scope and should be reported directly to the respective provider.
3. Authorization and Safe Harbor
If you act in good faith, comply with this policy, avoid privacy violations, service disruption, and data destruction, Körber will not initiate legal action against your security research activities. Researchers must immediately stop testing upon accessing sensitive information and notify Körber without delay.
4. Rules of Engagement
Researchers must: avoid denial-of-service testing; avoid social engineering, phishing, physical attacks, spam, or extortion; only access data necessary to validate a finding; not modify, delete, or exfiltrate data; not establish persistence or pivot to other systems; and maintain confidentiality until coordinated disclosure occurs.
5. Reporting a Vulnerability
Reports should be submitted through the Körber Vulnerability Disclosure Form. Reports should include affected product or asset, vulnerability description, reproduction steps, proof of concept, business impact, affected versions, and contact details.
6. What to Expect from Körber
Körber will acknowledge receipt of reports, perform triage and validation, communicate with the reporter during assessment, coordinate remediation activities, and provide updates where appropriate.
7. Vulnerability Handling Process
Körber follows a structured vulnerability handling process that includes report acknowledgment, technical validation, severity assessment, remediation planning, fix development and testing, and stakeholder communication. Where appropriate, Körber will publish security advisories or vulnerability disclosures after remediation or mitigation measures have been made available.
8. Coordinated Disclosure
Körber supports coordinated vulnerability disclosure. Public disclosure should occur only after remediation is available, mitigation guidance is published, or a mutually agreed disclosure date has been reached.
9. Recognition
Körber may acknowledge security researchers who help improve security, subject to legal, contractual, and privacy considerations. This program does not provide financial rewards unless explicitly stated.
10. Privacy and Confidentiality
Information submitted through the vulnerability reporting process will be processed in accordance with applicable data protection laws and Körber privacy requirements.
11. Exclusions
The following are generally excluded: spam, clickjacking with no security impact, missing security headers with no exploitability, rate limiting observations without impact, automated scanner output without validation, and vulnerabilities affecting unsupported products.
12. Contact Information
Primary reporting channel: Körber Vulnerability Disclosure Form.
Alternative contact: security@koerber.com.