The safety of our products is our highest priority. If you identify a safety risk, a vulnerability, or a cybersecurity incident related to a Schrack Technik product, we kindly ask you to report it to us immediately.
Once your report has been received, it will be reviewed by the responsible departments and processed in accordance with our internal procedures.
Where possible, we will provide:
Please note that acknowledging receipt of a report does not constitute confirmation that a vulnerability exists.
Whether and to what extent a report is classified as security-relevant depends on the technical validation and risk assessment.
Where legally required, Schrack will report identified actively exploited vulnerabilities and serious security incidents to the competent authorities in accordance with the applicable requirements of the Cyber Resilience Act (CRA).
CRA notifications are submitted via the Single Reporting Platform established by ENISA.
We kindly request that discovered vulnerabilities are not disclosed publicly before Schrack has had a reasonable opportunity to review the report and, where necessary, prepare or implement remediation measures.
Where possible, we aim to follow a coordinated disclosure process in appropriate consultation with the reporting party.
The CRA framework promotes transparency in vulnerability disclosure and supports the management of vulnerabilities throughout the entire product lifecycle.
We kindly request that security testing is conducted responsibly and does not involve any actions that:
This page does not constitute a waiver of any statutory rights, defenses, or legal positions of Schrack. Whether and to what extent a report is responded to, remedial measures are implemented, or information is published depends on the technical assessment, the risk situation, the product characteristics, and the applicable legal requirements.
The data collected through this form will be processed solely for the purpose of handling and documenting the report, ensuring product security, coordinating vulnerability disclosure, and fulfilling legal obligations.
As an alternative to the reporting form, you may also submit information about security vulnerabilities by email to cra-reporting(at)schrack.com. Please provide as much relevant information as possible to help us process and assess your report efficiently.