The security of the products, software solutions, and digital services developed and operated by RMG is our top priority. RMG welcomes the responsible reporting of vulnerabilities and security-related incidents by customers, operators, integrators, service partners, security researchers, and government agencies.
2. Purpose of this Directive
This policy defines the process for reporting, handling, assessing, and disclosing vulnerabilities. The goal is to identify risks early, minimize potential impacts, and ensure coordinated communication with those affected.
3. Scope
This policy applies to all products, firmware components, software products, web applications, communication solutions, and digital services developed and marketed by RMG.
4. Circumstances That Must Be Reported
Security vulnerabilities, authentication and authorization errors, privilege escalations, insecure configurations, vulnerabilities in third-party components, indications of active exploitation, opportunities for manipulation, and other security-related observations should be reported.
5. Issues That Should Not Be Reported Through This Reporting Channel
General support requests, complaints, warranty inquiries, product information, training requests, and sales-related matters should be submitted through the regular service channels.
6. Reporting Channels
RMG provides a security portal with a web form. Reports can also be sent to psirt@rmg.com. An OpenPGP key is available for encrypted communication of confidential information.
7. Contents of a Report
Reports should, whenever possible, include the product name, version, component status, description, impact, steps to reproduce the issue, log files, screenshots, proof-of-concepts, and contact information.
8. Anonymous Reports
Anonymous reports are permitted. However, it is recommended that you provide contact information for follow-up questions and coordination.
9. Processing Procedure
RMG confirms receipt of a report within five business days. An initial technical assessment is conducted within ten business days. This is followed by a technical analysis, risk assessment, development of countermeasures, notification of the customer, and closure of the report.
10. Coordinated Vulnerability Disclosure
RMG supports the coordinated disclosure of vulnerabilities. Reporters are asked to first report a vulnerability to RMG confidentially and to allow a reasonable period of time for investigation and remediation.
11. Expectations for Security Researchers
Responsible testing and the provision of technical evidence are permitted. Data manipulation, data theft, denial-of-service attacks, social engineering, and interference with customer systems are not permitted.
12. Confidentiality and Data Protection
Reports will be treated confidentially. Personal data will be used solely for the purpose of processing the report and will be handled in accordance with applicable data protection regulations.
13. Security Advisories
Confirmed vulnerabilities may be disclosed through security advisories. These include affected products, versions, risk assessments, impacts, and recommended mitigations.
14. Security Updates
RMG releases security updates, firmware updates, patches, hotfixes, and technical advisories to address confirmed vulnerabilities.
15. Communication with Those Affected
Depending on the criticality and impact, RMG informs customers, operators, integrators, government agencies, and other stakeholders about relevant risks and available protective measures.
16. Disclaimer
Reporting a vulnerability does not entitle the reporter to compensation, bounties, or other benefits. RMG reserves the right to evaluate and prioritize reported issues.