Skip to main content

Your security is our priority!


We take the security of our measurement and analysis systems seriously. On this page you will find how to report security vulnerabilities to us and how we handle them.

Reporting a security vulnerability 

Please report suspected vulnerabilities to  security@rotec-munich.de.

This also applies to vulnerabilities in third-party components included in our products.

The following information helps us process your report: the affected product and version, a description of the vulnerability, clear steps to reproduce it, the potential impact, and your contact details for any follow-up questions. Please do not send us any customer data or personal data of third parties.

This channel is intended exclusively for security reports. For general support requests, please contact support@rotec-munich.de.

How we handle your report 

We confirm receipt of your report within three business days. Following an initial review, we will get back to you within ten business days with an assessment and will keep you informed of any further developments.

We will coordinate the timing of any disclosure together with you. As a guideline, we aim for a period of 90 days from receipt of the report. Upon request, we will credit you by name in the associated advisory.

We will not pursue legal action against security researchers who act in good faith. This includes not extracting or publishing data, not disrupting services, and not disclosing information to third parties before remediation.


Security Advisories

Once a security update is available, we publish a security advisory and additionally inform affected customers and the reporter directly. Each advisory includes a description of the vulnerability, the affected products and versions, the impact, a severity rating based on CVSS, and remediation guidance.

In justified exceptional cases, we may postpone publication for as long as the risk of disclosure outweighs the benefit to users.


Security updates and support period 

We provide security updates free of charge for supported product versions. The support period is five years from the date the respective product version is placed on the market.

Last updated: August 2026