Security-Policy

Policy on Coordinated Vulnerability Disclosure

We are pleased that you have visited our website at www.m-pt.de and appreciate your interest in our company and our products. With this Cybersecurity Statement, we would like to inform you about our approach to and processes for cybersecurity. All product development and data processing at M-PT are conducted in strict compliance with applicable cybersecurity regulations.

1. Preface
This policy describes how security researchers, customers, and third parties can report vulnerabilities in our products to us, the rules that apply, and the internal process we follow—in accordance with the requirements of Regulation (EU) 2024/2847 (Cyber Resilience Act, “CRA”).

2. Handling of Good-Faith Reports (Safe Harbor)
Anyone who reports a vulnerability in good faith and in accordance with this policy, and who does no more than is necessary to demonstrate the vulnerability, is, in our view, acting within the scope of authorized security research. We will not take any legal action in response to such a report.

3. Rules for Security Research
a. What We Expect

  • Report any discovered or suspected vulnerability to us as soon as possible.
  • Test only on devices or systems that you own or for which you have explicit permission.
  • Use exploitation techniques only to the minimum extent necessary to demonstrate the vulnerability.
  • Give us a reasonable amount of time to address the issue before publishing details, proof-of-concept code, or tools (see Section 6).
  • Avoid disrupting customers’ ongoing operations (e.g., do not test products in production without the operator’s consent).

b. Prohibited Methods

  • Launching DoS/DDoS traffic attacks or stress tests against our systems or those of our customers.
  • Physically destructive testing on devices that are not your property.
  • Social engineering attacks (e.g., phishing) against employees or customers.
  • Large-scale scanning or automated reading of customer devices in the field.
  • Publication of unreleased firmware, key material, or complete exploit tools without prior consultation with us.

4. Scope
a. Products covered by this policy which are distributed by M-PT as the manufacturer, including:

  • Torque wrenches
  • Documentation software
  • Test bench, including software

b. Not covered by this policy

  • Components sourced from third parties (e.g., microcontroller/chipset firmware, operating system components): Please report vulnerabilities in these directly to the respective manufacturer. If it is unclear whether a component originates from us or a third-party manufacturer, please contact us in advance at the address listed in Section 5.
  • Devices or installations that have been individually customized or modified by customers.
  • Our customers’ IT infrastructure that is not part of our products (e.g., their own corporate network).

5. How to Report a Vulnerability

  • Email: security@m-pt.de
  • Please include:
    • Affected product, including model name and version
    • Description of the vulnerability,
    • Steps to reproduce the issue,
    • Evidence (screenshots, logs, proof-of-concept).
  • Reports can be submitted anonymously; however, providing contact information facilitates follow-up questions and allows us to keep you informed about the status of your report.
  • If the information provided is incomplete, we reserve the right not to pursue the report further

6. Our Commitments

Step Timeframe
Confirmation of receipt Immediately
Initial assessment / follow-up questions Within 24 hours
Status update on progress At least every 30 days until resolved
Notification of resolution Once a fix or workaround is available

7. Coordinated Disclosure
Our default remediation period is 90 days from confirmation that the vulnerability is valid. We ask that you refrain from publishing any details, proof-of-concept code, or exploit tools during this period.

  • In cases of particularly high severity (e.g., risk of injury to operators; see our internal risk assessment), a shorter remediation period may be mutually agreed upon.
  • In technically complex cases, we will proactively discuss an extension of the

remediation period with you.

  • Upon expiration of the remediation period or once a fix is available, we will publish information regarding the resolved vulnerability to the extent appropriate for the situation.

8. Statutory Reporting Obligations under the CRA (Art. 14)
If we determine that a vulnerability in one of our products is being actively exploited or that a serious security incident within the meaning of Art. 14(5) CRA has occurred, we follow the legally prescribed reporting process:

Timeframe Content Recipients
24 hours after becoming aware Early warning with initial information CSIRT (BSI/CERT-Bund) + ENISA
72 hours after becoming aware Supplementary detailed information CSIRT (BSI/CERT-Bund) + ENISA
14 days after a fix becomes
available
Complete final report CSIRT (BSI/CERT-Bund) + ENISA

We do not disclose the contact information of third parties to individuals reported as affected by an incident without their consent.

9. Security Lifecycle
For our products with digital components, we provide security updates for a support period of at least 5 years from the discontinuation of the respective model, in accordance with the CRA minimum requirement. The exact end of support will be communicated on a product-specific basis.

10. Changes to This Policy
We reserve the right to update this policy on an ongoing basis. The current version is published on our website and supersedes previous versions.

Version Date Change
1.0 September 10, 2026 Initial publication

 

M-PT Matjeschk-PowerTools GmbH & Co. KG
Cyber security officer
Am Sägewerk 11
01920 Ralbitz-Rosenthal, Deutschland
E-Mail: security@m-pt.de

As of September 10, 2026