Skip to main content

Vulnerability Disclosure Policy

WEINMANN Emergency LP welcomes reports of vulnerabilities, privacy issues, exposed data, or other security-related issues affecting our publicly accessible digital services and websites.

We support good-faith security research and Coordinated Vulnerability Disclosure (CVD). This policy does not provide for financial compensation or rewards. WEINMANN Emergency Medical Technology GmbH does not operate a bug bounty program.

Scope

This policy applies to publicly accessible production websites, web services, applications, and APIs intended for external use that are operated by or on behalf of WEINMANN Emergency LP and are under our control.

This includes:

  • *.weinmann-emergency.com
  • *.weinmann-connect.com
  • *.weinmann-emt.de

Out of scope are in particular:

  • development, preview, demo, admin, internal, and support environments;
  • third-party services or infrastructure not under our control;
  • customer environments or customer-managed integrations; and
  • medical devices and device-side functionality, unless explicitly stated otherwise.

Reporting Channel

Please report vulnerabilities to: Please enable JavaScript to render this link!

Anonymous reports are welcome, but they may limit our ability to ask follow-up questions or provide updates.

If your report contains sensitive information, we strongly encourage encrypted communication using our OpenPGP / PGP public key: https://www.weinmann-emergency.com/disclosure.weinmann-emergency.com.asc

Please note that unencrypted email should not be used to transmit sensitive information.

Please include, where possible:

  • the affected asset, product, or service;
  • a description of the issue;
  • steps to reproduce;
  • proof-of-concept details; and
  • your contact details, if you would like to receive updates from us.

What you can expect from us

If you act in good faith and in accordance with this policy, we will:

  • acknowledge receipt of your report within 5 business days;
  • review and assess your report;
  • prioritize remediation based on risk and severity;
  • strive to keep you reasonably informed; and
  • not initiate legal action or refer the matter for criminal complaint for good-faith security research conducted in line with this policy, to the extent legally permissible and within our control.

What we ask from you

When conducting security research, please:

  • act in good faith;
  • test only in-scope systems;
  • do not disrupt, destruct data, or violate privacy;
  • access only the minimum data necessary to demonstrate the issue;
  • stop testing and report immediately if you encounter personal data, health data, confidential business information, or other sensitive information;
  • do not use social engineering, phishing, physical attacks, denial-of-service techniques, malware, spam, or extortion; and
  • do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate it, ordinarily at least 90 days from your initial report, unless otherwise agreed or required by law.

If you are unsure whether your intended activity is consistent with this policy, please contact us before proceeding.

Data Protection

If you submit a report, we may process the personal data you provide for the purpose of receiving, reviewing, handling, and responding to your disclosure.

Further information on how we process personal data is provided in the Privacy Policy.

Hamburg, 01.09.2026