Vulnerability Disclosure Policy

Energiewerker GmbH

Februar 2024

Introduction

Energiewerker GmbH is committed to ensuring the security of its customers and employees by protecting their information. This policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities and to convey our preferences in how to submit discovered vulnerabilities to us.

This policy describes what systems and types of research are covered under this policy, how to send us vulnerability reports, and how long we ask security researchers to wait before publicly disclosing vulnerabilities.

We encourage you to contact us to report potential vulnerabilities in our systems.

Authorization

If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized we will work with you to understand and resolve the issue quickly, and Energiewerker GmbH will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known.

Guidelines

Under this policy, «research» means activities in which you:

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  • Only use exploits to the extent necessary to confirm a vulnerability’s presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command line access, or use the exploit to pivot to other systems.
  • Provide us a reasonable amount of time to resolve the issue before you disclose it publicly.
  • Do not submit a high volume of low-quality reports.

Once you’ve established that a vulnerability exists or encounter any sensitive data (including personally identifiable information, financial information, or proprietary information or trade secrets of any party), you must stop your test, notify us immediately, and not disclose this data to anyone else.

Test methods

The following test methods are not authorized:

  • Network denial of service (DoS or DDoS) tests or other tests that impair access to or damage a system or data
  • Physical testing (e.g. office access, open doors, tailgating), social engineering (e.g. phishing, vishing), or any other non-technical vulnerability testing

Scope

This policy applies to the following systems and services:

  • *.energiewerker.ch
  • *.landwerker.ch

Any service not expressly listed above, such as any connected services, are excluded from scope and are not authorized for testing. Additionally, vulnerabilities found in systems from our vendors fall outside of this policy’s scope and should be reported directly to the vendor according to their disclosure policy (if any). If you aren’t sure whether a system is in scope or not, contact us at info@energiewerker.ch before starting your research.

Reporting a vulnerability

We accept vulnerability reports via info@energiewerker.ch.

PGP Public Key:

—–BEGIN PGP PUBLIC KEY BLOCK—–

xsFNBGW/bf8BEAC6c3lFBfBAIln3vGLWERV5b5nhZYAMVYwExS1+8VzyZusn2fLe
vZFHP4GDgWx2/C0gsoTcleR+UYBkAhLDyBWeWPVm9SFD2Roz7TrnDFKal7jMJxnN
/gOB1b4LijKp5vzwsIX0qnRuGDWmWacHCM6MupSAK2pKWDGpkpSe7K93eNmvF71z
OExLlNdIxhcbnEE61PKmIzM3y29SHIQcETMvBJLASIe78PCTewTLoRPxnsQxHgaM
wluPCCLxQ+s6YiUWcpfE0hGcwOEdj7M8bmA3cxA+MPKwnUq+KNoErY9JW9pUNMhJ
LR2kvB45hxDf3fkmwOHDj7YUJEKmB06AnLF8g8hpiTVKUxzeXNcd0fzfpadjWTPb
XfDVrph61gLbdr2Nits6gBlDy86scXfTh27I8HZgoL3XDeXwjBBv4UFLd84MlfFZ
h+4n4p9DrytqKy/9xUhN7o4C9eYtldhDVGEf3aCR+Ggbch2Xr2cHofGjuP1VM8OX
isbb2sS7+hepPB21OrMC7VKhAUiRGUdToOh7KDtsQ2p8OsJ/7QTETmIVwD7HAjoJ
kuneDFfBa45SJpDmWQQ7bJgJ3iSgcympKkGH35f030R19v3MFSRG46S3+TQBMVyh
ZRaAzpqpHiluvBpa06hy6r0TUjdZw1KRWX4zv7PN9URBPL5Vyr3me+EWhwARAQAB
zUtNZWxjaGlvciBMaW1hY2hlciAtIEVuZXJnaWV3ZXJrZXIgR21iSCA8bWVsY2hp
b3IubGltYWNoZXJAZW5lcmdpZXdlcmtlci5jaD7CwY0EEwEIADcWIQTtaGStBK5N
Z+RTu6+K/Thj6573BAUCZb9uAQUJCWYBgAIbAwQLCQgHBRUICQoLBRYCAwEAAAoJ
EIr9OGPrnvcE+dUP/ROgl8DNqBasolZtnn7IXMHhkLBfjcfaex1mOXurD64cg7pt
cI3suSmzTw4TfjKHtuRFf/MiAgGNG9hPvhM8c4yfUGzBQrPWBrxwCTvjXtiBa5VM
902TwjInx8CYTvXswNwrqLMXFL/vvnT68mq62qhWVFNvdSV2z3Sv4Ek3OSIu301I
2F78CJT8XHvBuemL+FmIGK2whoRECQRGiCe479K6TX72DRmibEAoksYDbMyVlVGi
QOP1eid0GJg4FrIZ6oJllB6gcpAGEw4T6u3w/iJh4Xl3hpNQaAEFZAOmlKYG6ZDE
JV5FOTdAJfZbTi2nKf+CanM8th5kNLT+omDqauym/Nc8J34CQHP0HHqA03QD3jeJ
L0Rv8eUv5dcW3HZQSNKlCO4Hco4mFity+K4OQW6mM3TlVnX3c9IWwSpC6QwTNuRG
eHccIgSPUQZhaiAKF179vKXScPeLb2t1ipJcAsyHxfa+2gLusA+yLfwVHQAOPrOi
jlp/LO3gzRSDfB4/o7z7SHuw1tlPBcpK3bhpUhuPGjE/Mue/E65qg3B99lTk5Oeu
/yyYN5LUJWmNDgrLgFXNLyX5VQAX7J01X2VpsRE25uHieTUoHMpsvXPiAFIq34he
kjk6bDpbubGaiA4Z1peK5obTDD2KcNF3MaAJC+Hmaie5HPbPc50jWuZ1GhHOzsFN
BGW/bgEBEADHcMnM7dV0+6Tu0MpIbn3MmUVN6ftHAH5DkwS3rpOfQ1gnp79LEWhX
GUsoC6KbTi+VDn1fdskW3ZhGNira3yv7VMjbRWS2mNRi1LIq6ik06BRH5OAcfWMe
c1LGKAKmyURLoEdizE13neTHnE1XGgmKLenDd2rIeA6zbzp6xuElLOeZXh3DaoXE
mTydOlPK26aojLSaUJtgN38/qdNb9umBBmT9nNRqNCpourrTRa39TDYhFpCRWvHX
gCP0o/AmJ3kYnIJltvSfo5CnOnzRSsU0OequLgTs/9NiqnKXCMlcXICdYrgiwJK5
n85moq65LAjBC20uERl1dLnxT49QmSuRj43JKvnMSRF2aZf9mTO2ECr/+MVgHybs
8Q2QKf0WnbopiYtk/KQ0tVAAQxNDVMtRhtnEwZrAOIgFVy4TMBZsXnyfe7DX9lZN
+HrqVu96D102g08x8M7KKjN8Bi8fKtLxnKXDxYl6LH3+HOoxwVyMbdz6r2yi7YyN
iVkmAco4eedpKUttxgSJ1yRkTAR6j30JTsxSK5lTX3xE3kU1oqbtp2d6D49dBhh+
0sVw269QvvoXIlI4odEC8lyqT2tFVcuupI+X/NT20OtbesrSoVgKpnfviMVZ/f0e
mlRaKrzMd9C1lJt/xvtqG5XdBVMAVfCYUcgE/B7512/dZ4oQsIawKwARAQABwsF8
BBgBCAAmFiEE7WhkrQSuTWfkU7uviv04Y+ue9wQFAmW/bgIFCQlmAYACGwwACgkQ
iv04Y+ue9wSUnA//f0W3WFGGCm0rsnLKmV4/mlbcZzvqXvHQHnv/0WJuH+1ywhaW
PBbqFQHklTM5GPlPG5TQazsSyKia6LJV/p2ZMReQcELhB+kqSP4kfLQ/Pfk3kbS0
lj0JLLWViYSrPImuIz3D0lHXDSF4Y5x5xK0WkshgroH87UkpAGVpenHskgzxAPyB
dOApr8UhosGe83XTWCKGdt6b3O7xznFGVv5YdsaqLLFEgEZxwsl/9Nmt4nzeNTh0
vB1UaPuwUV4uoAqfAb0F0uaoD4AU8yICRJC2kHhiqsCkgu7p+Tm+IwqxJoTKY7pO
Jb8iFpRKlAI/saHU7Qq2RGCKbAn7bHhlEqjgdM8rMeXGM6nLU4pcHFaKZYPC/Pgk
0EzJjhVqvRDjW01Wf7nW9HJVhApp4ZJw1uGKx2FjD+TA3Uc57jw2iziZUy1pJ45F
eZCNJkKBWciCJxP1l2qDi4DQh3HFINdIQDcac6ehtq+ADAwGVCXbFzWnOzItk8Zk
WI7DKhKSWdaW0IkCQ9Z28BYFXIjE3rEfoWdl2ICjzbd9C5ymi+YIZs0VFP40gurI
Sf8XNmAKZbZVNlvm7wuwVPHJUvNN21WN1YYa4d72ivrXgYMRIoAhy31OGPv0B5+g
OfDT2Jy22HU9VE6oUb97Me51PIJ0XNxn/jtQDCD9k0ZjqWZR+H3J6UCq0T0=
=CQL3
-----END PGP PUBLIC KEY BLOCK-----

What we would like to see from you

In order to help us triage and prioritize submissions, we recommend that your reports:

  • Describe the location the vulnerability was discovered and the potential impact of exploitation.
  • Offer a detailed description of the steps needed to reproduce the vulnerability (proof of concept scripts or screenshots are helpful).
  • Be in English, if possible.

What you can expect from us

When you choose to share your contact information with us, we commit to coordinating with you as openly and as quickly as possible.

  • Within 3 business days, we will acknowledge that your report has been received.
  • To the best of our ability, we will confirm the existence of the vulnerability to you and be as transparent as possible about what steps we are taking during the remediation process, including on issues or challenges that may delay resolution.
  • We will maintain an open dialogue to discuss issues.

Questions

Questions regarding this policy may be sent to info@energiewerker.ch. We also invite you to contact us with suggestions for improving this policy.

Document change history

VersionDateDescription
1.04.2.2024First issuance.