Reporting of Software Security Vulnerabilities
If you have made an observation that indicates a potential vulnerability in the software or digital functions of our products or services, please report it by email to: product-cybersecurity@bollfilter.com
This reporting channel is intended exclusively for software- and IT-related security vulnerabilities. This includes, in particular, reproducible vulnerabilities in software, firmware, or communication interfaces.
The following are not covered by this reporting channel:
For such matters, please use the designated service or support channels.
Please include – where available – the following information:
If your report contains sensitive information, please indicate this accordingly. We will coordinate appropriate measures to ensure the protection of such data.
Handling of Vulnerability Reports
Boll & Kirch reviews reports of potential software security vulnerabilities using a risk-based assessment process. Where necessary for the evaluation of a report, we may contact the reporting party to request additional information.
If a reported vulnerability is confirmed, Boll & Kirch will assess its potential impact on the security of the affected products and determine appropriate mitigation measures. Where required by applicable law, notifications may be submitted to competent authorities and Computer Security Incident Response Teams (CSIRTs) in accordance with applicable legal requirements.
Submission of a report does not create any entitlement to compensation, bug bounty payments, or disclosure of internal investigation results.
This reporting channel is intended exclusively for cybersecurity vulnerability reports. General service requests, warranty claims, product complaints, or technical support requests will not be handled through this channel.