CDV Policy
Coordinated Vulnerability Disclosure

Coordinated Vulnerability Disclosure (CVD) Policy

Policy Völkel Mikroelektronik GmbH places great importance on the security of its products and is committed to remediating any discovered vulnerabilities promptly and responsibly. We invite everyone to report vulnerabilities in our products to us at psirt@voelkel.de. A PGP key is available for confidential reports:

Upon receipt of a report, you will receive a personal acknowledgment within 5 working days and an initial assessment within 10 working days—indicating whether the vulnerability has been confirmed or rejected, or if further time is required for analysis. If Völkel receives no response to a follow-up inquiry after 60 working days, the case will be closed. All reports are treated confidentially, and no personal data will be disclosed without your consent.

We report actively exploited vulnerabilities immediately to the European Vulnerability Database (EUVD), in accordance with the requirements of the EU Cyber ​​Resilience Act (CRA).

Völkel commits not to assert any claims against whistleblowers in connection with information submitted to us, provided the following conditions are met:

  • The whistleblower causes no harm to Völkel, our customers, or others.
  • The whistleblower does not compromise the privacy or security of our customers or the operation of our services.
  • The whistleblower does not violate criminal laws.

The whistleblower publishes details regarding the security vulnerability only after Völkel has confirmed that the vulnerability has been fully remediated.