/// 关闭

Product Safety & Security Incidents at IKA

Working Together for Safe Products and Secure IT Systems

IKA collaborates with security researchers, customers, partners, and CERTs to address security vulnerabilities and incidents quickly, transparently, and responsibly.

Reporting Product-Specific Vulnerabilities (PSIRT)

Have you discovered a vulnerability in an IKA product, software, firmware, or digital service?
Email: [email protected]

Reporting Security Incidents in Corporate IT (CSIRT)

Would you like to report a cyberattack, phishing incident, misuse of IKA systems, or any other IT security incident?
Email: [email protected]

Our Commitment

  • Confidential handling of all reports
  • Prompt acknowledgment and assessment
  • Responsible Disclosure of Vulnerabilities

Our Engagement

Collaboration with the Security Community

The security of our products and services is constantly evolving. Therefore, IKA welcomes the responsible reporting of security vulnerabilities by security researchers, customers, partners, suppliers, CERTs, and other stakeholders. We carefully review every report and work constructively with those who report them to minimize risks to customers, partners, and IKA.

Responsible Disclosure

Assurances to Reporters

When security research is conducted in good faith, responsibly, and in accordance with this policy, IKA commits to:
  • to treat your report confidentially
  • to promptly acknowledge receipt of the report
  • Carefully review and appropriately assess the report
  • To work constructively with you as needed
  • Not to take any legal action in connection with the report, provided that no unlawful or harmful acts have been committed
  • to disclose information about the reporter only with their consent or as required by law
  • to strive for coordinated disclosure, if disclosure is necessary

Reporting Process

1. Submit a Report

Please provide the following information if possible:
  • Affected product or system
  • Product, software, or firmware version
  • Description of the vulnerability or incident
  • Steps to reproduce the issue
  • Expected and actual behavior
  • Assessment of potential impacts
  • Screenshots, log files, or other evidence

2. Confirmation of Receipt

We will endeavor to acknowledge receipt of your report within five business days.

3. Assessment

As part of the assessment, IKA determines whether the report concerns an actively exploited vulnerability or a serious security incident and whether there are any legal reporting or disclosure obligations, particularly under the Cyber Resilience Act. If necessary, IKA will take the necessary steps with the relevant authorities and affected users.

4. Processing

Confirmed security vulnerabilities are handled according to their severity, and appropriate measures are taken. Affected customers or users are informed if this is necessary to minimize risk or due to legal requirements. Disclosure is coordinated and does not include any personal data of the person who reported the vulnerability.

5. Closure

The process is concluded when the report has been deemed unfounded or when appropriate measures have been completed or initiated.

Requirements for Valid Reports

A report should:
  • pertain to an IKA product or an IKA system
  • contain sufficient technical information
  • be reproducible and verifiable
  • do not consist exclusively of automated scanner results
  • Do not refer to information that is already publicly known

Code of Conduct for Security Researchers

We ask all reporters to adhere to the following guidelines:

Permitted

  • Security analyses conducted in good faith
  • Creation of a proof of concept (PoC), provided it is submitted to IKA on a strictly confidential basis
  • Responsible Disclosure of Vulnerabilities

Not Permitted

  • Modifying or deleting data
  • Access to personal data
  • Distribution of exploit code
  • Attacks on system availability
  • Social engineering
  • Phishing
  • Denial-of-Service Attacks (DoS/DDoS)
  • Activities outside the defined scope of testing

Contact

Product Security Incident Response Team (PSIRT)

Product security vulnerabilities in:
  • Products
  • Software
  • Firmware
  • Cloud services
  • APIs
  • Digital services
Email: [email protected]

Cyber Security Incident Response Team (CSIRT)

IT security incidents such as:
  • Cyberattacks
  • Phishing
  • Malware
  • Misuse of IKA systems
  • Security incidents in the company’s IT system
Email: [email protected]

Data Protection

All reports will be treated confidentially and used exclusively for the purpose of addressing the reported issue. Personal data is processed in accordance with applicable data protection regulations.