The safety of our products is our highest priority. If you identify a safety risk, a vulnerability, or a cybersecurity incident related to a Schrack Technik product, we kindly ask you to report it to us immediately.

How We Handle Reports

Once your report has been received, it will be reviewed by the responsible departments and processed in accordance with our internal procedures.

Where possible, we will provide:

  • an acknowledgement of receipt within 48 hours,
  • an initial expert assessment following an appropriate preliminary review, and
  • further updates on the processing status, where this is feasible and permissible from a security perspective.

Please note that acknowledging receipt of a report does not constitute confirmation that a vulnerability exists.

Whether and to what extent a report is classified as security-relevant depends on the technical validation and risk assessment.

Go to the reporting form

 

Scope

This point of contact is intended for reporting potential security vulnerabilities relating to:

  • Schrack products with digital elements,
  • associated software and firmware, and
  • manufacturer-provided product-related digital functionalities, where applicable.

The following should not be reported through this channel, in particular:

  • general service inquiries or complaints that are unrelated to security,
  • support requests not involving a cybersecurity vulnerability, and
  • data protection or privacy inquiries, unless they relate to a specific security incident.

Internal and Regulatory Follow-Up

Where legally required, Schrack will report identified actively exploited vulnerabilities and serious security incidents to the competent authorities in accordance with the applicable requirements of the Cyber Resilience Act (CRA).

CRA notifications are submitted via the Single Reporting Platform established by ENISA.

Responsible / Coordinated Disclosure

We kindly request that discovered vulnerabilities are not disclosed publicly before Schrack has had a reasonable opportunity to review the report and, where necessary, prepare or implement remediation measures.

Where possible, we aim to follow a coordinated disclosure process in appropriate consultation with the reporting party.

The CRA framework promotes transparency in vulnerability disclosure and supports the management of vulnerabilities throughout the entire product lifecycle.

No Misuse

We kindly request that security testing is conducted responsibly and does not involve any actions that:

  • impair the availability of systems,
  • unlawfully process personal data,
  • endanger third parties, or
  • violate applicable laws or regulations.

Liability and Legal Notice

This page does not constitute a waiver of any statutory rights, defenses, or legal positions of Schrack. Whether and to what extent a report is responded to, remedial measures are implemented, or information is published depends on the technical assessment, the risk situation, the product characteristics, and the applicable legal requirements.


Submit a Report

Guidelines

  • Please provide only the information necessary for processing your report.
  • Do not submit sensitive credentials, especially passwords.
  • Do not include personal data of uninvolved third parties.
  • Describe the issue as clearly, accurately, and systematically as possible.
  • Attach screenshots, log files, or other technical evidence where available.
  • In the event of an active security incident, please report it without delay.
  • Upon receipt of your report, you will be assigned a reference number and, if requested, receive an acknowledgement of receipt.


Privacy Notice

The data collected through this form will be processed solely for the purpose of handling and documenting the report, ensuring product security, coordinating vulnerability disclosure, and fulfilling legal obligations.

Step 1: Information About the Reporter

Full Name
(e.g. customer, distributor, integrator, security researcher, other)

Contact Us Alternatively by Email

As an alternative to the reporting form, you may also submit information about security vulnerabilities by email to cra-reporting(at)schrack.com. Please provide as much relevant information as possible to help us process and assess your report efficiently.