KOCO MOTION GmbH is committed to maintaining the security, integrity, and resilience of its products, systems, and services. In line with the requirements of the European Cyber Resilience Act (CRA), we encourage security researchers, customers, partners, and other stakeholders to responsibly report potential cybersecurity vulnerabilities.
This policy describes how vulnerabilities can be reported to KOCO MOTION and how such reports are handled.
Scope
This policy applies to:
- Products developed and distributed by KOCO MOTION GmbH
- Associated software, firmware, and digital services provided by KOCO MOTION
- Publicly accessible systems owned and operated by KOCO MOTION
The policy does not authorize activities that:
- Violate applicable laws or regulations
- Disrupt services or operations
- Access, modify, or delete customer or company data without authorization
- Involve social engineering, phishing, or physical attacks
- Include denial-of-service or ransomware-related activities
Reporting a Vulnerability
Security vulnerabilities may be reported via email to:
Please include the following information where possible:
- Description of the vulnerability
- Affected product, software version, or system
- Steps required to reproduce the issue
- Potential impact
- Proof-of-concept material, screenshots, or logs if available
- Your contact information for follow-up communication
Reports should be submitted in English or German.
Coordinated Vulnerability Disclosure
KOCO MOTION follows a coordinated vulnerability disclosure approach:
- We will acknowledge receipt of a report within 5 business days.
- We will assess the reported issue and determine its validity and severity.
- We may contact the reporting party for additional information.
- We will work to develop and implement appropriate corrective measures.
- Where required by applicable regulations, including the Cyber Resilience Act, relevant authorities and stakeholders will be informed.
KOCO MOTION requests that reporters:
- Keep details of the vulnerability confidential until remediation measures are available
- Avoid public disclosure before coordinated release
- Act in good faith and avoid privacy violations or operational disruption
Safe Harbor
KOCO MOTION will not pursue legal action against individuals who:
- Conduct security research in good faith
- Comply with this policy
- Avoid causing harm to KOCO MOTION, its customers, or partners
- Promptly report discovered vulnerabilities
This safe harbor applies only to activities consistent with this policy and applicable law.
Product Security and CRA Compliance
KOCO MOTION integrates cybersecurity considerations into product development and lifecycle management processes. Vulnerability handling is part of our ongoing commitment to:
- Secure product design
- Risk management
- Security updates and patch management
- Incident response
- Regulatory compliance under the EU Cyber Resilience Act
Data Protection
Any personal data submitted as part of a vulnerability report will be processed in accordance with applicable data protection laws, including the GDPR, and used solely for the purpose of handling the reported issue.
Contact
KOCO MOTION GmbH
Niedereschacher Str. 54
78083 Dauchingen
GERMANY
www.kocomotion.de
Security Contact: compliance@koco-group.com
Version: 1.0 Effective Date: 01-Aug-2026
Disclaimer
This content was created with the help of artificial intelligence (AI). Its content was throroughly reviewed and revised by the KOCO MOTION general management.