Skip to main content

For maximum product safety.
Neuberger-PSIRT.

The Neuberger-PSIRT (Product Security Incident Response Team) is your central point of contact for confidently reporting vulnerabilities and potential security gaps in our products.

For us, security is not a static condition, but an ongoing commitment. That's why our specialized security experts address every reported issue – quickly, transparently, and with the utmost care. Every report is promptly acknowledged and precisely evaluated and analyzed. We develop security updates to resolve the reported vulnerability or security gap. Transparency is paramount for us: We proactively inform you via security advisories and provide clear recommendations for action.

True to our philosophy of „Maximum Quality and best Service“ we consistently work to continuously improve the security and reliability of our products – for lasting trust and secure products you can depend on. 
 

We are therefore also a member of the Allianz für Cyber-Sicherheit beim Bundesamt für Sicherheit in der Informationstechnik (BSI). In doing so, we are consciously strengthening our network and collaboration with companies, associations, authorities and organizations with the shared goal of greater cybersecurity. 

Find out more

Security gaps and vulnerabilities.
Your options for contacting us.

How can you report security gaps and vulnerabilities to Neuberger-PSIRT?

If you have discovered a security gap or vulnerability in a Neuberger product, please preferably use the following contact form.

Personal Information
Your message to Neuberger-PSIRT
Spam protection
Legal

We use your data exclusively in accordance with our privacy policy.

Alternatively, you can also send us an email to: psirt@neuberger.net.

Please include the following information with your report:

  • Affected product: Name and software/firmware version
  • Problem description: Brief and clear explanation of the vulnerability
  • Impact: What could happen as a result of the security flaw?
  • Steps to reproduce: How can the problem be reproduced?
  • Your contact information: Name, email address, and phone number for follow-up questions.
     

Neuberger also supports encrypted communication via PGG. You can find our public PSG key in our Security.txt file. 

Reporters are requested to submit reports to the Neuberger PSIRT in either German or English.

Incident Management Process.
At Neuberger.

1. Confirmation

You will receive an automatic confirmation with a ticket ID and a contact number. Please keep this for future reference.

2. Assessment and Analysis

Our PSIRT team analyzes the report and assesses:

  • The severity of the security vulnerability
  • The potential impact on users
  • Which products and versions are affected

3. Fix and Security Update

We are developing a security update and will make it available to users. In certain cases, we may also provide workarounds until a complete security update is available.

4. Final Notification

You will receive a detailed summary of the measures taken and information on the availability of the security update.

FAQs.
PSIRT.

We do not currently offer a formal bug bounty program. However, we value collaboration with security researchers and are open to discussing this.

Please wait until we have released a security fix or agreed upon a firm timeline. This protects users from exploitation. We will coordinate the disclosure with you.

Report it anyway! It's better to receive a potentially false report than to overlook a real security vulnerability. Our team will assess it.

No, your name will not be published without your consent.

Only members of the PSIRT team and the directly affected development teams have access to the details. This is done on a "need-to-know" basis.

A penetration test is an authorized and controlled security test. This does not count as "active exploitation" by malicious actors. However, please report any vulnerabilities you find.

Confidentiality and Data Protection:
Please do not publicly disclose security vulnerabilities before notifying us. We will consult with you before releasing any further information. 
Your report will be treated confidentially. We will not share your data with third parties without informing you beforehand—unless this is necessary to improve the security of our products or to comply with legal requirements.