Meet us at IZB 2026 27. - 29.10.

Cavea® Trust & Security

Security and Vulnerability Disclosure

Security is a design requirement in every Cavea® product. If you have found a vulnerability, this page explains how to report it and what you can expect in return.

Contact

psirt@cavea.net
Preferred languages

German, English

Machine-readable policy
/.well-known/security.txt

Content

Security is a design requirement in every Cavea® product, from our Tribrid® tags to the software. No system is free of flaws, so we work with the security research community to find and fix them before they cause harm. This page explains how to report a vulnerability to us and what you can expect in return.


How to report

Send your report to psirt@cavea.net. To help us validate and fix the issue quickly, please include:

  • The affected product, component, or URL, and the version or environment where you observed it.
  • A clear description of the vulnerability and its potential impact.
  • Step-by-step instructions or a proof of concept that lets us reproduce the issue.
  • Any relevant logs, screenshots, or configuration details.

Please report in English or German. If your report contains sensitive details, let us know in your first message and we will arrange a secure channel.


Scope

This policy covers Cavea® hardware products, firmware, the software, and the web services operated under cavea.net. If you are unsure whether something is in scope, report it anyway and we will tell you.


What we ask of you

We ask researchers to act in good faith and to avoid harm while testing:

  • Do not access, modify, or delete data that is not your own, and stop as soon as you have confirmed a vulnerability exists.
  • Do not degrade, disrupt, or overload our services, and do not run denial-of-service tests.
  • Do not use social engineering, phishing, or physical attacks against our staff, customers, or facilities.
  • Give us a reasonable opportunity to fix the issue before disclosing it publicly.

Our commitment to you

When you report in good faith and follow this policy, we commit to the following:

We consider security research conducted under this policy to be authorized. We will not pursue or support legal action against researchers who act in good faith and stay within the guidelines above. If legal action is initiated by a third party against someone who complied with this policy, we will make it known that their actions were authorized.


Coordinated disclosure

We follow a coordinated disclosure approach. We ask that you keep the details of any vulnerability confidential until we have released a fix, and we aim to resolve valid reports within 90 days. If a fix will take longer, we will tell you why and agree on a timeline together. Where relevant, we will assign a CVE identifier and publish an advisory once the fix is available.

3 days
Acknowledgement of your report

10 days
Initial assessment shared

90 days
Target for a released fix


Out of scope

The following are generally not treated as security vulnerabilities: reports from automated scanners without a demonstrated impact, missing security headers or best-practice recommendations with no exploitable effect, self-inflicted issues, and vulnerabilities in third-party services we do not operate. We still appreciate the heads-up and will forward reports to the relevant party where we can.


Machine-readable contact

A security.txt file describing how to reach us is published at https://www.cavea.net/.well-known/security.txt, following RFC 9116.

The essentials

Email
psirt@cavea.net

Preferred languages Deutsch, Englisch

Machine-readable policy
/.well-known/security.txt

Policy Version 1.0 — Last updated on Sept. 10th 2026 2026.