Report a security vulnerability

The security of our products is important to us. If you discover a vulnerability in a product of SoCom Informationssysteme GmbH, please report it to us. We handle every report, regardless of whether you are a customer, a security researcher or a business partner.

Contact

E-Mail 
security_at_socom.de

Postal address
SoCom Informationssysteme GmbH
Raiffeisenstr. 44
86381 Krumbach-Niederraunau
Germany

Languages
German / English

Please use this channel for security reports wherever possible — it reaches the appropriate contacts directly.

Encryption: We accept reports unencrypted. If you would like to encrypt your report, contact us briefly at the same address and we will agree on a suitable method. Please do not send exploit code over a channel whose security has not been verified if confidentiality matters to you; ask us first.

Please do not use public channels (forums, social networks, public issue trackers): premature disclosure puts the affected users at risk.

If a report nevertheless reaches us through support or a personal contact, we handle it in exactly the same way — it is passed to the security reporting contact without delay, and all time limits under this policy run from the moment we first receive it.

What to include in a report

To help us respond quickly, the following information is useful:

  • the affected product and version (for example TIKOS 6 2026.1, texPortal 2026.2, texOrder 2025.1),
  • a description of the vulnerability and its possible impact,
  • steps to reproduce the issue, ideally with screenshots, log extracts or a proof of concept,
  • the environment in which you identified the vulnerability (your own installation, a test system, a customer system),
  • your contact details, and whether you wish to be named.
 

Our commitments

When      What to expect from us
        

Within 3 working days    

          Acknowledgement of receipt, including a contact person and a case reference

Within 10 working days    

          An initial technical assessment: confirmed / not confirmed / further information required, with an estimate of severity

ongoing    

          A status update at least every 30 days until the case is closed

after remediation    

          Information on the version in which the vulnerability has been fixed, and how that version is distributed

Our disclosure period is 90 days from receipt of your report. Within that period we aim to provide and publish a fix. If a fix demonstrably takes longer — for instance because an equipment manufacturer or a third-party supplier is involved — we will agree an extension with you. We ask you to refrain from disclosing the vulnerability yourself until publication.

We are legally required to report actively exploited vulnerabilities to the European Union Agency for Cybersecurity (ENISA) and the German Federal Office for Information Security (BSI) within 24 hours. This applies independently of the 90-day disclosure period, and we will inform you accordingly.

Recognition

At your request, we will name you in our security advisory and in the release notes. We do not pay rewards — there is no bug bounty programme. Please tell us whether you wish to be named, credited under a pseudonym, or not named at all.

What we assure you — and what we ask of you

If, during your research, you

  • test only systems for which you hold credible, written authorisation,
  • do not retrieve, alter, publish or retain third-party data for longer than necessary to substantiate the finding,
  • do not impair the availability of our systems or our customers’ systems (no load testing, no denial-of-service attempts),
  • do not carry out any social engineering, phishing or physical attacks against employees,
  • report your finding to us first and comply with the agreed period,

then we will treat your research as good-faith security research and will neither initiate nor instigate legal action against you.

Please note: we cannot give this assurance for tests involving installations operated by our customers — in such cases the customer, as the operator, decides. Please test your own systems only.

Fixed vulnerabilities

We publish information about fixed vulnerabilities, including a description, impact, severity and remediation guidance, at https://www.socom.de/security and in the release notes for the relevant version.

There are currently no published security advisories.

Out of scope

Reports concerning systems not provided by SoCom; configuration recommendations without security impact; findings from automated scanners without a demonstrable security impact; vulnerabilities in products whose support period has ended — we assess such vulnerabilities, but cannot commit to a fix. To find out whether your product is still within its support period, contact support_at_socom.de.

Support - Portal KONTAKTA OSS