Quality and sustainability

Quality, environmental responsibility and information security are managed through certified systems held by the relevant r2p legal entities.

Quality management
ISO 9001:2015
Environmental
ISO 14001:2015
Information security
ISO/IEC 27001:2022
Type approval
KBA, Germany

Quality across the product lifecycle

r2p’s management systems support the full product lifecycle, from capturing requirements and controlling changes to feeding field experience back into engineering and service.

This structured approach helps r2p deliver consistent products, services and project outcomes while supporting continuous improvement.

Environmental responsibility

r2p works to reduce environmental impact through responsible development, resource use and documented environmental management practices.

ISO 14001 certification provides an independently assessed framework for maintaining and improving that work.

CRA / CVD Process

Vulnerability Handling and Disclosure Process

r2p is committed to the security of our products and services. We believe that coordinated vulnerability disclosure benefits our customers and the broader digital community.

This policy describes how security researchers and the public can report potential security vulnerabilities in r2p products and the commitments we make in response.

Scope

This policy applies to vulnerabilities in all software products developed and supplied by r2p GmbH and its subsidiaries.

Vulnerabilities in third-party components incorporated into or affecting the security of an r2p product are within the scope of this policy and may be reported to us.

Products that are no longer within their defined support period may fall outside the scope of this policy. However, we encourage the reporting of security vulnerabilities affecting any r2p product, including unsupported products.

Vulnerabilities solely affecting third-party products or services are outside the scope of this policy.

Rules for Security Research

The following testing activities are not permitted under this policy:

  • Destructive testing or intentional modification or deletion of data.
  • Installation of malware, backdoors or other mechanisms intended to maintain persistent access.
  • Accessing, copying or exfiltrating data beyond the minimum necessary to demonstrate the vulnerability.
  • Denial-of-service (DoS/DDoS) attacks or other testing that may impair the availability or stability of systems or services.
  • Social engineering, including phishing, impersonation and other attempts to obtain information through deception.
How to Report a Vulnerability

To report a security vulnerability, contact our security team:

Reports containing sensitive information should be encrypted using our published PGP key (see below). Do not report security vulnerabilities through public issue trackers, social media or support tickets.

We accept reports in English, German and Danish.

Information to Include

To help us investigate and assess the vulnerability, please include as much of the following information as possible:

  • Affected product, software version and relevant configuration (if known).
  • A clear description of the vulnerability, including its potential security impact.
  • Steps to reproduce the vulnerability and, where appropriate, a proof of concept, screenshots, logs or other supporting information.
  • Any indication that the vulnerability is being actively exploited, if known.
  • The date and time the vulnerability was discovered, if known.
  • Your contact details (optional).

Reports may be submitted anonymously. However, providing contact information enables us to request additional information and provide status updates.

What Happens After You Report

When a vulnerability is reported to r2p, the following steps are taken:

  • Acknowledgement: We will acknowledge receipt of the report within 3 business days.
  • Initial assessment: Within 7 business days, we will review and assess the vulnerability.
  • Communication: If you have provided contact information, we will keep you informed of material progress and may contact you for additional information.
  • Remediation: Confirmed vulnerabilities are addressed based on their severity, exploitability and potential impact. We aim to remediate vulnerabilities without undue delay and will coordinate an appropriate disclosure timeline with the reporter where applicable.
  • Notification: Where appropriate, we will notify affected users when a vulnerability has been remediated or when mitigations or security updates are available. We will also notify the reporter, provided contact information has been supplied.

If available, preliminary versions of software fixes may be provided to the reporter for verification.

Coordinated Disclosure

r2p is committed to coordinated vulnerability disclosure (CVD). We ask reporters not to publicly disclose vulnerability details before the agreed disclosure date and to coordinate any planned publication with r2p.

We will work with the reporter in good faith to coordinate an appropriate disclosure timeline. The timeline will take into account the severity and potential impact of the vulnerability, the risk to users, evidence of active exploitation, and the availability of mitigations or security updates.

If a vulnerability presents an immediate or significant risk to users or is known to be actively exploited, r2p may accelerate remediation, mitigation and disclosure activities as appropriate.

Following remediation or the availability of appropriate mitigations, r2p may publish information about the vulnerability to help affected users understand the risk and take appropriate action. Publication may be limited where necessary for security, legal, contractual or privacy reasons.

PGP Key File

Fingerprint 02B7 9A42 FA6E D399 3A39 A2E9 4946 B3F4 60B4 B5D2

Download PGP Key File

ISO certified

Certification is held by individual legal entities. Each document below is therefore listed under the r2p company to which it applies.

r2p GmbH Flensburg, Germany

r2p UK Systems Ltd Crawley, United Kingdom

ISO 27001 certificate

ISO/IEC 27001:2022

Valid to January 2029 · PDF

Download
Cyber Essentials Plus certificate

Cyber Essentials Plus

Technically verified · PDF

Download
CHAS certificate certificate

CHAS certificate

Health and safety · PDF

Download

Need a document for a tender?

If you need a certificate, scope statement or compliance document that is not listed here, contact r2p and we will provide the appropriate document.