Report Vulnerabilities
Security Pledge
LAUDA takes the security of its products seriously. If you have discovered a security vulnerability in one of our products, we ask that you report it to us confidentially. We will carefully review every report and work with you to find a coordinated solution.
This page serves to fulfill our obligations as a manufacturer under Regulation (EU) 2024/2847 of the European Parliament and of the Council of October 23, 2024, on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act, CRA).
Please also read our detailed CRA Statement (PDF) for further information on our cybersecurity measures.
Reporting Channel
Email: psirt@lauda.de
(PSIRT = Product Security Incident Response Team)
Scope of the Reporting Center
In-Scope
This reporting center applies to LAUDA products with digital elements whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network—including the firmware, software, and third-party components. We accept reports of vulnerabilities in included third-party components and coordinate their resolution with the respective component manufacturer.
Out-of-Scope
What should a report include?
Please include the following information in your report if possible:
Process and SLAs for CRA Reports
Starting September 11, 2026, LAUDA will be subject to the reporting requirements under the Cyber Resilience Regulation (EU) 2024/2847. For actively exploited vulnerabilities and serious security incidents, the following deadlines must be met when reporting to the relevant authorities (CSIRT/ENISA):
| Step | Deadline |
|---|---|
| Early warning to authorities/CSIRTs | ≤ 24 hours after becoming aware |
| Report with preliminary assessment to authorities/CSIRTs | ≤ 72 hours |
| Final report (actively exploited vulnerabilities) | Within 14 days of a fix or mitigation becoming available |
| Final report (serious security incidents) | ≤ 1 month after the report |
Process and SLAs for Other Security-Related Reports
For reports not covered by the CRA reporting requirements (above), the following internal processing deadlines apply:
| Step | Deadline |
|---|---|
| Acknowledgment of receipt | ≤ 1 business day |
| Initial substantive assessment | ≤ 7 business days |
| Risk assessment and prioritization | At our discretion |
| Fix/Patch or Mitigation | Based on risk and availability |
| Coordinated disclosure | After resolution, in coordination with the parties involved |
PGP Key
Our public PGP key is available for the encrypted transmission of your report:
| Property | Value |
|---|---|
| Key ID | 49DB91210B9E5F65 |
| Fingerprint | 9A1F 8D16 460C 9799 98FA 9B2C 49DB 9121 0B9E 5F65 |
| Valid until | June 9, 2029 |
> Download PGP key (pgp-key.asc)
This page is intended exclusively for reporting security vulnerabilities in LAUDA products.
For general support inquiries, please contact: service@lauda.de
There are already three products on your comparison list.
To compare other products, please delete one of the products on your comparison list.