Reporting vulnerabilities under the Cyber Resilience Act

The security of our products and services is important to us, and we welcome reports of potential security vulnerabilities in digital offerings developed, provided or operated by FORMAT Software Service GmbH.

You can use this form to responsibly report vulnerabilities in our software solutions, web applications, customer portals, APIs and product-related online services.

To facilitate a swift investigation, please provide details of the affected solution or service, the version, the affected function or URL, whether the issue can be reproduced, and any potential impact. Please only access data or systems to the extent strictly necessary to demonstrate the vulnerability, and refrain from taking any actions that could compromise availability, stability or third parties.

Please do not publish any details before we have agreed on a coordinated disclosure together.

We will usually acknowledge receipt of your report within three working days, investigate the matter as quickly as possible and treat your information confidentially. We prioritise valid reports internally and will keep you informed of the progress of the investigation to an appropriate extent.

Please note that FORMAT does not currently operate a bug bounty programme and that these guidelines do not constitute general permission to interfere with systems or data.


Your report

    Information about the vulnerability


    Your contact details in case we need to get in touch

    Information regarding data protection and the information obligations under Articles 13 and 14 of the GDPR concerning the processing of your personal data can be found in the privacy policy.

    arrow_upward