Safety
Reporting potential security issues
Responsible Disclosure of Security Vulnerabilities
Introduction
REO AG attaches the utmost importance to the security of its products and services. We welcome reports of potential vulnerabilities in our products and systems. We would like to be informed as soon as possible so that we can take the necessary measures to protect our customers and strengthen the confidentiality, availability and integrity of our systems. If you have identified a security vulnerability, we ask that you report it to us in accordance with the principles of responsible disclosure. To do so, please complete the form below entitled ‘Reporting an incident or vulnerability’ or send us an email at security@reo.de.
Required information
To ensure your enquiry is processed promptly, please provide us with the following information:
- Product affected: Product name, model and version
- Type of vulnerability: Description of the identified issue or security vulnerability.
- Steps to reproduce the issue: A detailed instruction or a PoC (Proof of Concept) so that we can replicate the issue.
- Tools used: Details of the applications, programs or tools used to identify the vulnerability
- Date and Time: The date and time the test was carried out.
- Supporting evidence (optional): images, code snippets or videos that illustrate the issue.
- Contact details: Your contact details in case we need to get in touch with you. If you wish to remain anonymous, you can use an anonymous email service or submit the form without providing any personal details. We take anonymous reports seriously too.
- Credit: Please indicate whether you would like to be credited by name should the issue be resolved.
(Note: When using our online form, you will be guided step by step through all the information required. See below.)
Rules of Engagement for Whistleblowers
To ensure your safety and avoid jeopardising the process, please observe the following rules:
- Confidentiality: Do not disclose any information about the vulnerability or security risks to third parties until REO has resolved the issue.
- Proportionality: Do not take any measures that go beyond what is strictly necessary to demonstrate the vulnerability.
- No misuse: Do not exploit this vulnerability or access any customer data. Do not access, alter, delete or publish any third-party data.
- Data protection: Do not store any confidential or personal data to that you may have accessed during your investigation.
- Integrity: The deletion, alteration or damage of data and systems is prohibited.
- Availability: Do not carry out any actions that could lead to service interruptions or system failures (e.g. no DoS/DDoS attacks).
- Prohibited methods: Physical attacks, social engineering, phishing, the installation of malicious software (malware) and the theft of login credentials are strictly prohibited.
What REO assures
- Confirmation of receipt: You will receive confirmation that your report has been received within 3 working days.
- Transparent handling: Following the analysis (technical assessment and risk classification), we will inform you of the outcome, the planned measures and the expected timeline for rectifying the vulnerability, where possible and appropriate.
- Compliance with the law: All investigations must be carried out in accordance with the applicable laws and regulations.
- Resolution notification: We will notify you once the vulnerability has been successfully resolved.
- Co-ordinated disclosure: A public announcement will only be made once the problem has been resolved, and always in consultation with you.
- Acknowledgement: If you wish, we will name you as the person who discovered the vulnerability.
Exclusions
This program is intended solely for reporting IT security vulnerabilities in products and systems. It is not intended for:
- General feedback or customer complaints
- Notifications regarding temporary website downtime
- Phishing emails or general fraud
- Technical support requests concerning REO products
For general enquiries or support requests, please use our standard contact page.
Compensation / Reward
REO does not offer any financial compensation or reward for identifying vulnerabilities.
Legal notice / Non-compliance
Provided that you comply with the above rules, REO will not take any legal action against you. In the event of any breach of these rules (e.g. data manipulation, causing a system failure, blackmail), REO expressly reserves the right to take appropriate civil and/or criminal legal action