Reporting Cybersecurity Vulnerabilities Responsibly

Our contact point for security-related reports within the range of the Cyber Resilience Act (CRA).

If you discover a vulnerability in a JULABO product, in our software, or on our websites, we would like to hear about it. This page explains how to securely submit security reports to us, how we handle them, and what protections you can expect as the reporting company.

What We Mean by a Security Advisory

A security advisory is a notice regarding a technical vulnerability that could allow our units, software, interfaces, or websites to be tampered with, read, or disrupted without authorization. Typical examples include inadequately secured interfaces, authentication vulnerabilities, data leaks, and firmware updates that can be manipulated.

Please direct general product inquiries, operational issues, or service requests to our regular customer support or  technical service —not through this page.

Reports that are not security-related will be ignored if submitted through this channel!

Description of your problem and the products you used

Product & Version

Which unit, which software/firmware version, and serial number (if applicable).

Description & Reproduction

What is the problem? How can it be reproduced? What effects do you see?

Contact & Confidentiality

How can we contact you if we have any questions? Would you like to remain anonymous?

Direct contact:

Email: productsecurity@JULABO.com
PGP Public Key: available starting September 2026

Mailing Address:

JULABO GmbH
Attn: Research & Development / Product Security
Gerhard-Juchheim-Straße 1
77960 Seelbach
Germany

Registration Form

Type of Vulnerability, Affected Component/Function
specific steps or requirements
Has it already been shared with third parties or published?
Disclosure Shared
Salutation
Company
Fields marked with are mandatory.

How We Handle Reports

Our Promise to You

  • You will receive a confirmation of receipt immediately upon receipt of your message.
  • Initial feedback on the content within 6 calendar days.
  • Confidential treatment — we will not disclose your identity to third parties without your consent.
  • No legal action against security researchers who act in good faith, adhere to our disclosure policy, and do not unlawfully access, modify, or publish third-party data.
  • Recognition — upon request, we will include you in our list of security researchers who have contributed to the security of JULABO products.

Guidelines for Security Research

  • Please give us sufficient time to analyze and resolve the vulnerability before making it public. The standard period is 90 days from confirmation of receipt.
  • Do not test on our customers’ production systems — please test only on your own units or with explicit permission.
  • No access to third-party personal data, no downloading, modifying, or publishing of such data.
  • No denial-of-service tests against our infrastructure.
  • Please comply with applicable law.

FAQ

JULABO does not maintain a public bug bounty program. We acknowledge researchers by name upon request.

Yes. Please use PGP for this, or do not provide any contact information. However, in that case, we will not be able to answer any questions.

You will first receive a confirmation of receipt. We will review the report internally, analyze the risk, and develop a fix. You will be kept informed of our progress.

Depending on the severity. We address critical vulnerabilities as a priority and fix simple bugs within the next regular update cycles.