Kern AG’s CVD policy

Coordinated vulnerability disclosure

The security of our products and IT infrastructure is a high priority for Kern AG. We recognize that even carefully developed software may contain vulnerabilities. We therefore value the contribution of security researchers and everyone who helps us identify and remediate such vulnerabilities.
 

How to contact us

Kern AG welcomes security reports from anyone, regardless of whether an existing service agreement is in place. A non-disclosure agreement (NDA) is not required as a condition for submitting a report.

We accept reports in German or English. If your report contains confidential information, we recommend sending it by encrypted and digitally signed email.

If you prefer to remain anonymous, you can also submit a report using our online form. Please note that our ability to investigate anonymous reports is limited, as we may not be able to ask follow-up questions or provide feedback on the outcome.

Your report should include the following information:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the vulnerability or, where available, proof-of-concept code or screenshots
  • The affected product, product version, and system environment
  • Information on whether the vulnerability has already been disclosed elsewhere
     

What you can expect from us

We treat every report as strictly confidential and will not disclose your personal data to third parties without your explicit consent. You will receive a personal acknowledgment of receipt within five business days and a substantive response within ten business days. This response may confirm the vulnerability, explain why we do not accept the report, or provide our assessment of the issue. Throughout the process, you will have a dedicated point of contact.

Provided that reporters comply with the following principles, Kern AG will not take legal action against them:

  • Security research and testing must be conducted in a way that does not cause harm to third parties.
  • Testing must be limited to systems you own or systems for which the affected customer has given explicit prior permission.
  • All applicable laws and regulations must be complied with.
  • The principle of coordinated disclosure must be respected. Details of the vulnerability must not be made public before the agreed disclosure date.
  • The availability, integrity, and confidentiality of customer systems and data must not be compromised at any time during testing or disclosure.
     

How we handle reports

  1. Report: You contact us through one of the channels listed below under "Security contact at Kern AG".
  2. Triage and analysis: Our team reviews the report and attempts to reproduce the described behavior. If necessary, we will contact you for clarification or request additional technical details.
  3. Remediation: We work with the responsible development teams to develop a fix or mitigation. We keep you informed of our progress and, where appropriate, may provide pre-release fixes for verification.
  4. Coordination with authorities: If we become aware that a vulnerability is being actively exploited, we will notify the competent national CSIRT, such as CERT-Bund, without undue delay. We will continue to keep the CSIRT informed of new findings, mitigation measures, and relevant timelines.
  5. Disclosure: Once a vulnerability has been confirmed and verified, we aim to disclose it publicly within 90 days. In consultation with the national CSIRT, this period may be extended by a further 90 days if additional time is genuinely required. Upon request, we will also arrange for the vulnerability to be added to the European Vulnerability Database operated by ENISA (EUVD). 

We consider a case closed once the vulnerability has been remediated and, where applicable, disclosed, or once we have provided the reporter with a reasoned explanation as to why no further action will be taken. Except in the case of anonymous reports, where we have no means of contacting the reporter, we will notify you without undue delay once the case has been closed.
 

Security contact at Kern AG

Questions regarding the security of our products or IT infrastructure, as well as new vulnerability reports, can be submitted through the following channels.
 

Vulnerability in a Kern AG Product, Service, or System

Vulnerability in Kern AG’s IT Infrastructure

Anonymous Vulnerability Report

Version 1.0, September 1, 2026: Initial publication