Vulnerability Disclosure Policy

Introduction

This policy describes the process for reporting security vulnerabilities in software, services, systems, and infrastructure maintained or operated by INSIDE M2M GmbH.

The scope of this policy includes M2MGate as a product, as well as systems, services, and software components developed by INSIDE M2M that are directly technically connected to M2MGate. This may include customer-specific components, services, or systems that use M2MGate as a base platform.

This policy also applies to customer-specific developments that were explicitly commissioned by a customer, developed by INSIDE M2M, and technically operated by INSIDE M2M.

In addition, this policy covers systems used by INSIDE M2M for software development, build, deployment, maintenance, and operation of the components, services, and systems described above.

This policy is intended to support responsible vulnerability disclosure and to help ensure that security issues can be reported, assessed, addressed, and communicated in a structured manner.

What is considered a security issue

A security issue is any weakness, vulnerability, misconfiguration, or defect that may negatively affect the confidentiality, integrity, or availability of systems, services, components, software, or data within the scope of this policy.

This includes, but is not limited to:

  • Issues that may affect the availability of one or more services, components, or systems described in this policy.
  • Issues that may put the integrity of data at risk, including unauthorized corruption, tampering, deletion, or modification of data.
  • Issues that may compromise the confidentiality of data owned, processed, or managed by INSIDE M2M GmbH, including unauthorized disclosure, access, theft, leakage, or exfiltration of restricted or private information.
  • Authentication, authorization, access control, or session management weaknesses.
  • Injection vulnerabilities, cross-site scripting, insecure direct object references, remote code execution, privilege escalation, or comparable technical vulnerabilities.
  • Vulnerabilities in development, deployment, or operational systems that could affect the security of products, services, or customer environments.

Reporting a security issue

Security issues should be reported by email to: psirt@inside-m2m.de

If the report contains confidential information, personal data, sensitive technical details, exploit information, credentials, logs, or other protected information, please encrypt the email using the PGP key provided by INSIDE M2M GmbH before sending it.

-----BEGIN PGP PUBLIC KEY BLOCK-----
mDMEanmvkhYJKwYBBAHaRw8BAQdA6DW/OIEL5Ch74x2mySi0yCVvpe+ukhh38wup
TjruV060PVByb2R1Y3QgU2VjdXJpdHkgSW5jaWRlbnQgUmVzcG9uc2UgVGVhbSA8
cHNpcnRAaW5zaWRlLW0ybS5kZT6IrwQTFgoAVxYhBDgp9FuAMGv2yC3vrDQuYAGW
LtC0BQJqea+SGxSAAAAAAAQADm1hbnUyLDIuNSsxLjEyLDAsMwIbAQULCQgHAgIi
AgYVCgkICwIEFgIDAQIeBwIXgAAKCRA0LmABli7QtPIlAPsHSRssj+n4i6riGykh
4ugKTcI+fzbjnWmTAwIbyOJrUAEAg3DTmwlm+Id05Qmp3R9Q0MV6/D/Xo4dbOOtv
ZdgwFQo=
=6OLj
-----END PGP PUBLIC KEY BLOCK-----

Reports submitted to this address will not be publicly visible at the time of reporting. Information about a reported vulnerability will only be shared as necessary for investigation, remediation, coordination, legal compliance, or communication with affected parties.

What to include in a security issue report

To help us investigate and resolve the issue efficiently, please include as much relevant information as possible.

Helpful information includes:

  • A clear description of the suspected vulnerability.
  • Step-by-step instructions to reproduce the issue.
  • The affected product, service, system, component, customer-specific development, or environment.
  • If applicable, whether the issue occurs while logged in, logged out, or under a specific role or permission level.
  • Proof-of-concept code, screenshots, logs, request and response examples, or other supporting material, if available.
  • Browser name and version, operating system, client software, plugin, library, or dependency versions, where relevant.
  • Any known OWASP category, CWE identifier, or related vulnerability classification.
  • Any assigned CVE identifier, if already known.
  • An assessment of the potential impact, if known.
  • Any information that may help us reproduce, understand, verify, or remediate the issue.

Please do not include unnecessary personal data or customer data in the report. If such information is required to demonstrate the issue, please minimize it as far as possible and use encrypted communication.

What happens after a security issue is reported

After receiving a security issue report, INSIDE M2M GmbH will review the submitted information and handle the report according to its internal security and software maintenance processes.

We will generally take the following steps:

  • Acknowledge receipt of the report, provided that valid contact information is available.
  • Determine whether the reported issue is considered a security issue within the scope of this policy.
  • Determine whether one or multiple systems, services, components, customers, or environments are affected.
  • Create internal tickets for the relevant components, services, systems, or operational areas.
  • Attempt to reproduce and verify the reported issue.
  • Assess the severity, impact, exploitability, and urgency of the issue.
  • Prioritize remediation based on risk and affected systems.
  • Develop and review a fix or mitigation.
  • Create software releases according to the applicable release processes.
  • Deploy updates, mitigations, or configuration changes to affected systems, services, and components where INSIDE M2M GmbH is responsible for technical operation.
  • Coordinate with affected customers, partners, suppliers, or other relevant parties where required.
  • Inform the reporter about relevant progress or resolution, where appropriate and where contact information is available.

The exact handling, timeline, and communication may depend on the severity, complexity, affected systems, contractual obligations, and legal or regulatory requirements.

Public disclosure

Please do not publicly disclose a reported vulnerability before INSIDE M2M GmbH has had a reasonable opportunity to investigate and remediate the issue.

If public disclosure is appropriate or legally required, INSIDE M2M GmbH will coordinate the timing and content of such disclosure with affected parties where possible.

Because the affected software, systems, documents, and customer-specific developments may be closed source, confidential, or protected by contractual obligations such as non-disclosure agreements, public details may be limited.

Crediting reporters

INSIDE M2M GmbH does not provide an official public crediting program for vulnerability reporters.

As many affected systems, software components, and documents are closed source, customer-specific, confidential, or protected by non-disclosure agreements, public attribution may not be possible.

INSIDE M2M GmbH does not operate a public bug bounty program. Reports are therefore not eligible for monetary rewards unless explicitly agreed in writing in advance.

For serious vulnerabilities that are reported responsibly, confidentially, and before exploitation, INSIDE M2M GmbH may, at its own discretion, express appreciation to the reporter in an appropriate manner.

INSIDE M2M GmbH values responsible security research and good-faith reporting.

If a security researcher reports a vulnerability voluntarily, confidentially, and before exploiting it or causing harm, INSIDE M2M GmbH does not intend to initiate legal action against the reporter solely for discovering and reporting the vulnerability.

This applies only if the researcher acts in good faith and avoids actions that may cause damage, disruption, unauthorized access to data, degradation of services, privacy violations, or other harm.

Researchers must not:

  • Access, modify, delete, copy, or exfiltrate data that does not belong to them.
  • Disrupt, degrade, or interrupt systems, services, or networks.
  • Use social engineering, phishing, physical attacks, or coercion.
  • Install malware, backdoors, persistence mechanisms, or unauthorized tools.
  • Attempt to pivot into systems beyond what is strictly necessary to demonstrate the vulnerability.
  • Publicly disclose the vulnerability before coordinated remediation.
  • Violate applicable laws, contracts, confidentiality obligations, or data protection requirements.

If sensitive data is encountered during research, the researcher must stop testing immediately, report the finding confidentially, and avoid further access, copying, or disclosure.

Contact

Security vulnerabilities should be reported to: psirt@inside-m2m.de

For confidential reports, please use the PGP key provided by INSIDE M2M GmbH: security-pgp-key.txt