Our Commitment to Security

At koenig-pa GmbH, we take product security seriously. We are committed to identifying, assessing, and addressing security vulnerabilities in a timely and responsible manner.

We welcome vulnerability reports from customers, partners, security researchers, and other members of the security community.

Reporting a Vulnerability

If you believe you have identified a potential security vulnerability in one of our products, you may full out our reporting form or contact us at: security@koenig-pa.de

To help us investigate the issue, please include as much of the following information as possible:

  • Product name and exact version
  • Description of the vulnerability
  • Steps required to reproduce the issue
  • Potential security impact
  • Relevant logs, configuration details, crash dumps, or proof-of-concept information
  • Your contact details, if you would like us to provide updates

Please do not publicly disclose the vulnerability before we have had a reasonable opportunity to investigate it and coordinate the disclosure process.

For further information, please refer to our Vulnerability Disclosure Policy.

Vulnerability Handling Process

We handle vulnerability reports in accordance with our Coordinated Vulnerability Disclosure process.

After receiving a report, we will:

  1. Acknowledge receipt.
  2. Investigate and validate the reported issue.
  3. Assess its severity and potential impact on affected products and users.
  4. Develop a security update or recommend appropriate mitigation measures.
  5. Keep the reporter informed of significant progress, where appropriate.
  6. Coordinate disclosure and customer notification as necessary.

Where applicable, we fulfil the vulnerability reporting and user notification obligations established by the EU Cyber Resilience Act and other applicable legislation.

Customer Notification

Where necessary, affected customers and users will be informed about confirmed vulnerabilities and available corrective or mitigation measures.

Depending on the nature of the vulnerability and the affected products, notifications may be provided through:


Security advisories


Customer support channels


Support tickets


Direct email notifications

Security updates are provided in accordance with the applicable product support period and product lifecycle policy.

Security Advisories

Information about confirmed vulnerabilities and related security updates may be published in our Security Advisories.

A security advisory may include:

  • Affected products and versions
  • Severity and potential impact
  • CVE identifier, where applicable
  • Recommended mitigation measures
  • Fixed product versions
  • References to relevant updates or documentation

Example

Security Advisory SA-2026-001

  • Product: KPA EtherCAT Master
  • Severity: High
  • CVE: CVE-2026-XXXX
  • Fixed in Version: 1.8.4

Security Documentation

For supported products, we may provide security-related information and documentation, including:


Security advisories


Supported product and version information


Information about security updates


Software Bill of Materials (SBOM), where applicable


Other relevant technical information

For security documentation or SBOM-related enquiries, please contact security@koenig-pa.de.

Contacts

Security Reports and Enquiries

security@koenig-pa.de

Technical Support

support@koenig-pa.de