Reporting Cybersecurity Vulnerabilities Responsibly
Our contact point for security-related reports within the range of the Cyber Resilience Act (CRA).
If you discover a vulnerability in a JULABO product, in our software, or on our websites, we would like to hear about it. This page explains how to securely submit security reports to us, how we handle them, and what protections you can expect as the reporting company.
What We Mean by a Security Advisory
A security advisory is a notice regarding a technical vulnerability that could allow our units, software, interfaces, or websites to be tampered with, read, or disrupted without authorization. Typical examples include inadequately secured interfaces, authentication vulnerabilities, data leaks, and firmware updates that can be manipulated.
Please direct general product inquiries, operational issues, or service requests to our regular customer support or technical service —not through this page.
Reports that are not security-related will be ignored if submitted through this channel!
Description of your problem and the products you used
Product & Version
Which unit, which software/firmware version, and serial number (if applicable).
Description & Reproduction
What is the problem? How can it be reproduced? What effects do you see?
Contact & Confidentiality
How can we contact you if we have any questions? Would you like to remain anonymous?
Direct contact:
Email: productsecurity@JULABO.com
PGP Public Key: available starting September 2026
Mailing Address:
JULABO GmbH
Attn: Research & Development / Product Security
Gerhard-Juchheim-Straße 1
77960 Seelbach
Germany
Registration Form
How We Handle Reports
Our Promise to You
- You will receive a confirmation of receipt immediately upon receipt of your message.
- Initial feedback on the content within 6 calendar days.
- Confidential treatment — we will not disclose your identity to third parties without your consent.
- No legal action against security researchers who act in good faith, adhere to our disclosure policy, and do not unlawfully access, modify, or publish third-party data.
- Recognition — upon request, we will include you in our list of security researchers who have contributed to the security of JULABO products.
Guidelines for Security Research
- Please give us sufficient time to analyze and resolve the vulnerability before making it public. The standard period is 90 days from confirmation of receipt.
- Do not test on our customers’ production systems — please test only on your own units or with explicit permission.
- No access to third-party personal data, no downloading, modifying, or publishing of such data.
- No denial-of-service tests against our infrastructure.
- Please comply with applicable law.
FAQ
JULABO does not maintain a public bug bounty program. We acknowledge researchers by name upon request.
Yes. Please use PGP for this, or do not provide any contact information. However, in that case, we will not be able to answer any questions.
You will first receive a confirmation of receipt. We will review the report internally, analyze the risk, and develop a fix. You will be kept informed of our progress.
Depending on the severity. We address critical vulnerabilities as a priority and fix simple bugs within the next regular update cycles.