Security
simatec ag welcomes reports of security vulnerabilities in our products and services. The report form at the bottom of this page is our single point of contact for those reports, and this is our policy for handling them.
You do not need an account, and you do not need to be a customer. If you are unsure whether what you found is a vulnerability, report it anyway — we would rather review a false positive than miss a real issue.
What to Include
The more of this you can give us, the faster we can confirm and fix an issue:
- Which product, service or URL is affected
- What an attacker could do with the issue
- The steps needed to reproduce it
- How you would like to be credited, if at all
What Happens Next
- We acknowledge your report within three business days, if you left an email address.
- We tell you whether we have reproduced it, and our initial assessment, within ten business days.
- We keep you informed while we work on a fix, and we tell you when it ships.
- We publish an advisory for issues affecting products already in the field, and we credit reporters who want to be named.
We ask that you give us reasonable time to fix an issue before disclosing it publicly. We will not ask you to delay indefinitely.
Scope
This policy covers products and services operated or manufactured by simatec ag, including the my.simatec platform, the simatec APIs, and the connected hardware we place on the market.
Services operated by third parties on our behalf are in scope only for issues affecting simatec ag data or customers. Vulnerabilities in third-party products themselves belong with that vendor.
Working Safely
When investigating, please:
- Only access data that is yours, or that belongs to a test account you control
- Stop as soon as you have confirmed an issue, rather than exploring further
- Never run denial-of-service tests, send spam, or use social engineering against our staff, customers or partners
- Never modify or delete data that is not yours
If you follow this policy in good faith, simatec ag will not pursue or support legal action against you for your research. If a third party brings action against you for research that followed this policy, we will make that adherence known.
We do not currently operate a paid bug bounty.
Last updated 08/03/2026