Responsible Disclosure Policy

Responsible entity: Truma Gerätetechnik GmbH & Co. KG, Wernher-von-Braun-Straße 12, 85640 Putzbrunn, Germany

Safe, reliable and trustworthy products are a high priority for Truma. Truma takes the security of its products and digital services seriously and continuously works to identify potential risks to customers, users and systems at an early stage, assess them appropriately and reduce them effectively. Reports from security researchers, customers and partners make an important contribution to this objective.

1. Purpose and Principle

Truma supports responsible and coordinated reporting of security vulnerabilities. This Policy explains how potential vulnerabilities in Truma products with digital elements and related digital services can be reported and how Truma handles such reports.

2. Reporting and Encryption

Please report potential security vulnerabilities in German or English to security@truma.com. Please use Truma’s published OpenPGP key for email submissions. Sensitive technical information, in particular exploit details, technical sample code demonstrating the vulnerability (proof-of-concept code), credentials, keys, personal data or confidential system information, should only be submitted PGP-encrypted.

3. What to Include in a Report

Where possible, please provide the product, model and version; a description of the suspected vulnerability and its impact; reproduction steps, test environment and tools used; relevant evidence including clearly marked proof-of-concept or exploit code; information on active exploitation or particular risks; and your contact details and any reference or advisory numbers. Proof-of-concept or exploit code and information on active exploitation or particular risks should be submitted PGP-encrypted.

4. Handling and Coordinated Disclosure

Truma generally acknowledges receipt of an actionable report within two business days and assesses the reported vulnerability based on risk. Truma may coordinate handling with affected manufacturers, coordinators, Computer Security Incident Response Teams (CSIRTs) or authorities.

The internal assessment, prioritisation and handling of reports is carried out in accordance with the processes established for this purpose at Truma.

Truma supports coordinated vulnerability disclosure. Please do not disclose information about a vulnerability publicly before Truma has been able to assess the report, evaluate risks and initiate appropriate corrective or mitigating measures. Statutory or regulatory reporting obligations remain unaffected.

5. Rules for Responsible Testing

Testing must be lawful, proportionate and conducted in a manner that avoids harm. Please do not access third-party data, devices, accounts or networks, alter or delete data, or perform availability, load, denial-of-service, social-engineering, phishing, malware or physical attacks. If third-party or personal data becomes visible unintentionally, stop the investigation and inform Truma.

6. Confidentiality, Recognition and Legal Limits

Truma generally treats reports as confidential and processes personal data only to the extent necessary to receive, assess and handle the report, communicate, maintain evidence or comply with legal obligations. Please submit personal data only where necessary for the report. Access to personal data is limited to the persons and functions involved in handling the report, risk assessment, remediation, coordination with affected third parties or compliance with legal obligations. Disclosure to third parties is made only where necessary for validation, risk assessment, remediation, user notification, coordinated disclosure or statutory or regulatory obligations. Truma may publicly recognise reporting persons upon request. Where reporting persons act in good faith, comply with this Policy, do not cause harm, do not infringe third-party rights and do not disclose information before coordinated disclosure, Truma will generally not pursue claims against them in relation to the report and the associated policy-compliant security testing. This Policy does not establish a bug bounty programme or any entitlement to compensation or other consideration. It does not constitute an engagement. Unlawful conduct or breaches of this Policy remain unaffected.

7. Contact

Security Contact for product security and vulnerability reports

Email: security@truma.com

PGP-Key: Download