Product Security at JAT Jenaer Antriebstechnik GmbHJAT Product Security Incident Response Team (PSIRT)
For the products and solutions of JAT Jenaer Antriebstechnik GmbH, quality, reliability, and information security are of paramount importance. Cybersecurity aspects are therefore considered from the very beginning of the development process and are continuously reviewed throughout the product lifecycle. Our goal is to ensure the security of our products and systems over their entire lifecycle.
The identification and responsible handling of potential vulnerabilities are key elements of this approach. JAT regards the discovery and disclosure of security vulnerabilities as a shared responsibility among manufacturers, customers, partners, and the security community, helping to maintain a consistently high level of security.
Coordination of incoming reports of potential vulnerabilities and security incidentsResponsibilities of the JAT PSIRT Team
The Product Security Incident Response Team (PSIRT) at JAT Jenaer Antriebstechnik serves as the central point of contact for all product-related security reports concerning our products, solutions, and services.
The PSIRT coordinates the handling of incoming reports regarding potential vulnerabilities and security incidents. Its responsibilities include:
- Analyzing and assessing reported vulnerabilities
- Coordinating internally with development teams and product experts
- Planning and implementing appropriate mitigation measures
- Providing transparent communication to customers regarding confirmed vulnerabilities
If a security vulnerability is confirmed, JAT will publish the corresponding Security Advisories. These advisories are issued as soon as appropriate mitigations or updates become available. In critical cases, an initial advisory may be published before an update is available in order to inform users about potential protective measures and risk mitigation options.
JAT appreciates and welcomes reports of potential security vulnerabilities.Vulnerability Reporting
JAT welcomes vulnerability reports from customers, security researchers, partners, authorities, and other members of the security community. Collaboration is conducted in a professional and trustworthy manner at all times.
The handling of vulnerability reports follows the principle of Coordinated Vulnerability Disclosure (CVD). The objective is to analyze and remediate vulnerabilities in cooperation with the reporter before any details are disclosed publicly.
To enable efficient processing, reporters are encouraged to provide as much relevant information as possible, including:
- Contact information for follow-up questions
- The affected product, including model and version details
- A description and classification of the vulnerability
- The potential impact of the vulnerability
- Any available technical evidence, proof of concept, or reproduction steps
If additional information is required for the analysis, the PSIRT will contact the reporter directly.
Upon request, the discoverer of a vulnerability may be acknowledged appropriately after the vulnerability has been remediated and publicly disclosed.
Submission of a Vulnerability Report
Contact the PSIRT Team
Reports concerning product-related security issues or potential vulnerabilities in JAT products may be submitted to the JAT Jenaer Antriebstechnik PSIRT team using the contact details provided below. For the transmission of sensitive information, the use of encrypted communication is recommended.
Reports may be submitted in either German or English.
The link to our Security Advisories can be found below:
Reports may generally be submitted anonymously via the telephone number or contact form provided below without disclosing any personal contact information. However, incomplete information may make it more difficult to reproduce and resolve the reported issue. Therefore, we would greatly appreciate it if you could provide your contact details for any necessary follow-up questions.
Any personal data you provide will, of course, be processed in accordance with our Privacy Policy.