- Cavea GmbH
- Security-Policy
Security and Vulnerability Disclosure
Security is a design requirement in every Cavea® product. If you have found a vulnerability, this page explains how to report it and what you can expect in return.
Contact
German, English
Content
Security is a design requirement in every Cavea® product, from our Tribrid® tags to the software. No system is free of flaws, so we work with the security research community to find and fix them before they cause harm. This page explains how to report a vulnerability to us and what you can expect in return.
How to report
Send your report to psirt@cavea.net. To help us validate and fix the issue quickly, please include:
- The affected product, component, or URL, and the version or environment where you observed it.
- A clear description of the vulnerability and its potential impact.
- Step-by-step instructions or a proof of concept that lets us reproduce the issue.
- Any relevant logs, screenshots, or configuration details.
Please report in English or German. If your report contains sensitive details, let us know in your first message and we will arrange a secure channel.
Scope
This policy covers Cavea® hardware products, firmware, the software, and the web services operated under cavea.net. If you are unsure whether something is in scope, report it anyway and we will tell you.
What we ask of you
We ask researchers to act in good faith and to avoid harm while testing:
- Do not access, modify, or delete data that is not your own, and stop as soon as you have confirmed a vulnerability exists.
- Do not degrade, disrupt, or overload our services, and do not run denial-of-service tests.
- Do not use social engineering, phishing, or physical attacks against our staff, customers, or facilities.
- Give us a reasonable opportunity to fix the issue before disclosing it publicly.
Our commitment to you
When you report in good faith and follow this policy, we commit to the following:
- We will acknowledge your report within three business days.
- We will validate the issue and share our initial assessment within ten business days.
- We will keep you informed as we work on a fix, and we will let you know when it is resolved.
- We will credit you for the discovery if you would like us to, and respect your wish to stay anonymous if you prefer.
We consider security research conducted under this policy to be authorized. We will not pursue or support legal action against researchers who act in good faith and stay within the guidelines above. If legal action is initiated by a third party against someone who complied with this policy, we will make it known that their actions were authorized.
Coordinated disclosure
We follow a coordinated disclosure approach. We ask that you keep the details of any vulnerability confidential until we have released a fix, and we aim to resolve valid reports within 90 days. If a fix will take longer, we will tell you why and agree on a timeline together. Where relevant, we will assign a CVE identifier and publish an advisory once the fix is available.
Acknowledgement of your report
10 days
Initial assessment shared
90 days
Target for a released fix
Out of scope
The following are generally not treated as security vulnerabilities: reports from automated scanners without a demonstrated impact, missing security headers or best-practice recommendations with no exploitable effect, self-inflicted issues, and vulnerabilities in third-party services we do not operate. We still appreciate the heads-up and will forward reports to the relevant party where we can.
Machine-readable contact
A security.txt file describing how to reach us is published at https://www.cavea.net/.well-known/security.txt, following RFC 9116.
The essentials
Email
psirt@cavea.net
Preferred languages Deutsch, Englisch
Machine-readable policy
/.well-known/security.txt
Policy Version 1.0 — Last updated on Sept. 10th 2026 2026.