Skip to main content
Press enter to search

Contact

Contact Form
[Translate to US - english:] [Translate to UK - english:] Stage Image

Product Security

Have you found a possible security vulnerability in one of our products? Report it here directly to our Product Security Incident Response Team (PSIRT). We acknowledge receipt within two business days.

No support channel. Please direct any questions regarding quality, warranty, or general functionality to our regular customer service channel.

01.

Report received

Via the reporting platform or by email, anonymously if you prefer.

02.

Acknow­ledgement

Within two business days, sent by our PSIRT.

03.

Assessment and remediation

A realistic view of next steps, plus updates until the issue is fixed.

04.

Coordinated disclosure

Publication as a security advisory, with timing agreed together.

Coordinated Vulnerability Disclosure Policy (CVD-Policy)

The security of our products is a high priority for us. We welcome working with customers, partners and security researchers who help us identify and fix potential vulnerabilities in our products with digital elements. This policy explains how to report a vulnerability to us and what you can expect from us in return.

Scope

This policy covers security vulnerabilities in Brinkmann Pumps products with digital elements — in particular connected pump controllers, IoT sensors, frequency converters with firmware as well as associated software, apps and online services. It also applies to vulnerabilities on our websites.

Please do not use this channel for quality, warranty or purely functional questions; instead contact our regular customer support.

How to report a vulnerability

  1. Contact us via the Brinkmann reporting platform or by email. For sensitive details, please use encrypted communication.

  2. Describe the issue as precisely as possible (see the information below) so that we can understand and reproduce it.

  3. Give us time to investigate and remediate, and keep the vulnerability confidential until then (coordinated disclosure).

 

Helpful information to include in your report:

  • Affected product or URL, including model and firmware/version (if known).

  • Description of the vulnerability with proof of concept, exploit steps or network captures, where available.

  • Potential impact and prerequisites for exploitation.

  • Whether the vulnerability has already been disclosed publicly — and by whom.

  • A way to contact you for follow-up questions (anonymous reports are also welcome).

Our commitments

If you follow this policy, we commit to:

  • Acknowledge receipt of your report within two business days.

  • Investigate the reported vulnerability and give you a realistic assessment of the next steps.

  • Keep you informed of progress and notify you once the vulnerability has been fixed.

  • Treat your report and your data confidentially.

Coordinated disclosure

We ask you to keep a reported vulnerability confidential and not to share or publish it to third parties until we have made a fix available. Immediate public disclosure exposes customers to unnecessary risk. We agree the timing and scope of any publication together with you.

Safe Harbor

NO LEGAL ACTION FOR GOOD-FAITH RESEARCH

Brinkmann Pumps will not pursue legal action against individuals who report vulnerabilities in good faith and in accordance with this policy. 

 

This requires that you:
 

  • do not cause harm and do not compromise the privacy, safety or operation of our customers;
  • only test as far as necessary to demonstrate the vulnerability, and do not access, modify or store third-party data;
  • comply with applicable laws and do not disclose the vulnerability before coordination.

Out of scope

  • Attacks that affect the availability of services (e.g. DoS/DDoS), as well as spam or social-engineering attacks against employees.

  • Physical access to facilities, devices or sites.

  • Testing that affects customer systems or production environments without explicit consent.

Staying informed

Confirmed vulnerabilities that require action are published as security advisories, including affected versions, CVE identifier, rating and remediation guidance. We announce new advisories via a mailing list (newsletter) and an RSS/CSAF feed.

Data protection

Personal data you provide to us as part of a report (e.g. contact details and the contents of your report) is processed solely to handle and remediate the reported vulnerability and to communicate with you. The legal basis is our legitimate interest in the security of our products (Art. 6(1)(f) GDPR). Reports may be submitted anonymously if you prefer. Details on processing, retention periods and your data-subject rights can be found in our privacy notice

Frequently asked questions

The Cyber Resilience Act is an EU regulation setting security requirements for products with digital elements. Among other things, it requires manufacturers to offer a clear channel for reporting vulnerabilities and to provide security updates. This page is that channel.

Yes. Simply describe what you observed and name the product and version. Our PSIRT will clarify everything else with you.

Our Product Security Incident Response Team. It receives reports, assesses them, coordinates remediation and publishes security advisories.

Yes. Without a way to contact you, however, we cannot ask follow-up questions or keep you informed of progress.

Contact

cra@brinkmannpumps.atlassian.net
Acknowledgement within two business days