Skip to content

Procedure for the Coordinated Disclosure of Vulnerabilities (CVD Policy – Coordinated Vulnerability Disclosure Policy)

Manufacturer: beyonnex.io GmbH
Version: 1.0
Created on: 3 September 2026
Last amended: 3 September 2026
Next review: 3 September 2027

Purpose and scope

We, beyonnex.io GmbH, welcome responsible reports of suspected vulnerabilities affecting our products with digital elements. Security researchers and other individuals who identify a potential vulnerability may report it to our security team by email. Please provide sufficient information to enable us to understand, reproduce, assess and, where appropriate, resolve the reported issue.

This procedure applies to vulnerabilities affecting products with digital elements from beyonnex.io GmbH.

We review this procedure at least once a year and keep it up to date.

How to report a vulnerability

Vulnerabilities can be reported to us at the following email address (cyberresilience@beyonnex.io):

Report a vulnerability by email

We accept vulnerability reports by email only.

We handle all incoming vulnerability reports to the best of our knowledge and belief. No report is closed solely on the basis of one person's assessment.

A vulnerability is considered valid if it concerns a product with digital elements from beyonnex.io GmbH.

Confidentiality and protection of reporters

We treat every vulnerability report as confidential to the extent permitted by law. This does not apply to information required for the coordinated disclosure of a vulnerability.

Personal data relating to a reporter will not be disclosed to third parties without the reporter's explicit consent, unless this is required in connection with an official investigation.

We will not initiate criminal proceedings against reporters provided that they comply with the requirements and principles of this procedure. This does not apply where criminal intent was or is evident.

We remain available for a confidential dialogue throughout the CVD process.

We expressly welcome reports of vulnerabilities, as they help us improve the security of our products. However, submitting a vulnerability report does not create any entitlement to a financial reward, bug bounty or other remuneration.

Information to include in your report

To help us assess and investigate a reported vulnerability efficiently, please provide as much relevant information as possible. Where applicable, a complete report should include the following:

  • Name of the affected beyonnex.io GmbH product or component and its firmware or software version.
  • A clear description of the suspected vulnerability, including its cause and the identified security impacts.
  • Clear, detailed step-by-step instructions enabling the vulnerability to be reproduced and verified independently.
  • A description of any specific configurations, operating conditions, permissions, authentication requirements or other prerequisites needed to reproduce the issue.
  • A description of the possible consequences of successful exploitation. This includes the affected assets, data, systems or users, as well as the level of access an attacker could obtain.
  • Where available: a proof of concept, test case, screenshots, log files or exploit code demonstrating the issue.
  • Any additional technical details, indicators, logs or supporting evidence that may assist in validating and assessing the vulnerability.

Excluded matters

The following matters generally fall outside this coordinated vulnerability disclosure process:

  • Vulnerabilities that have already been publicly disclosed, assigned a CVE number, or remedied through a security update or other mitigation. This does not apply if the report contains material new information, identifies previously unknown security impacts, or indicates that the remedy is incomplete or ineffective.
  • Vulnerabilities in products, software, services or versions that have reached the end of their life cycle (end of life) or that we no longer support.
  • Vulnerabilities in versions for which we have already recommended an upgrade or migration to a supported version and where the reported issue has been remedied in the recommended version.
  • Findings without a relevant security impact. These include purely informational observations, general security recommendations or weaknesses that cannot reasonably be exploited in the affected environment.
  • Matters primarily involving social engineering, phishing, spam or attacks on employees or customers of beyonnex.io GmbH or other third parties, and which are not based on a vulnerability in a product or service of beyonnex.io GmbH.
  • Reports that have been generated exclusively by automated scanning tools and do not contain sufficient information to reproduce or validate the issue.
  • Vulnerabilities in third-party products or services that we do not develop, maintain, distribute or operate. Such issues should be reported to the relevant manufacturer or service provider.