Quality across the product lifecycle
r2p’s management systems support the full product lifecycle, from capturing requirements and controlling changes to feeding field experience back into engineering and service.
This structured approach helps r2p deliver consistent products, services and project outcomes while supporting continuous improvement.
Environmental responsibility
r2p works to reduce environmental impact through responsible development, resource use and documented environmental management practices.
ISO 14001 certification provides an independently assessed framework for maintaining and improving that work.
CRA / CVD Process
Vulnerability Handling and Disclosure Process
r2p is committed to the security of our products and services. We believe that coordinated vulnerability disclosure benefits our customers and the broader digital community.
This policy describes how security researchers and the public can report potential security vulnerabilities in r2p products and the commitments we make in response.
Scope
This policy applies to vulnerabilities in all software products developed and supplied by r2p GmbH and its subsidiaries.
Vulnerabilities in third-party components incorporated into or affecting the security of an r2p product are within the scope of this policy and may be reported to us.
Products that are no longer within their defined support period may fall outside the scope of this policy. However, we encourage the reporting of security vulnerabilities affecting any r2p product, including unsupported products.
Vulnerabilities solely affecting third-party products or services are outside the scope of this policy.
Rules for Security Research
The following testing activities are not permitted under this policy:
- Destructive testing or intentional modification or deletion of data.
- Installation of malware, backdoors or other mechanisms intended to maintain persistent access.
- Accessing, copying or exfiltrating data beyond the minimum necessary to demonstrate the vulnerability.
- Denial-of-service (DoS/DDoS) attacks or other testing that may impair the availability or stability of systems or services.
- Social engineering, including phishing, impersonation and other attempts to obtain information through deception.
How to Report a Vulnerability
To report a security vulnerability, contact our security team:
- E-mail: productSIRT@r2p.com
Reports containing sensitive information should be encrypted using our published PGP key (see below). Do not report security vulnerabilities through public issue trackers, social media or support tickets.
We accept reports in English, German and Danish.
Information to Include
To help us investigate and assess the vulnerability, please include as much of the following information as possible:
- Affected product, software version and relevant configuration (if known).
- A clear description of the vulnerability, including its potential security impact.
- Steps to reproduce the vulnerability and, where appropriate, a proof of concept, screenshots, logs or other supporting information.
- Any indication that the vulnerability is being actively exploited, if known.
- The date and time the vulnerability was discovered, if known.
- Your contact details (optional).
Reports may be submitted anonymously. However, providing contact information enables us to request additional information and provide status updates.
What Happens After You Report
When a vulnerability is reported to r2p, the following steps are taken:
- Acknowledgement: We will acknowledge receipt of the report within 3 business days.
- Initial assessment: Within 7 business days, we will review and assess the vulnerability.
- Communication: If you have provided contact information, we will keep you informed of material progress and may contact you for additional information.
- Remediation: Confirmed vulnerabilities are addressed based on their severity, exploitability and potential impact. We aim to remediate vulnerabilities without undue delay and will coordinate an appropriate disclosure timeline with the reporter where applicable.
- Notification: Where appropriate, we will notify affected users when a vulnerability has been remediated or when mitigations or security updates are available. We will also notify the reporter, provided contact information has been supplied.
If available, preliminary versions of software fixes may be provided to the reporter for verification.
Coordinated Disclosure
r2p is committed to coordinated vulnerability disclosure (CVD). We ask reporters not to publicly disclose vulnerability details before the agreed disclosure date and to coordinate any planned publication with r2p.
We will work with the reporter in good faith to coordinate an appropriate disclosure timeline. The timeline will take into account the severity and potential impact of the vulnerability, the risk to users, evidence of active exploitation, and the availability of mitigations or security updates.
If a vulnerability presents an immediate or significant risk to users or is known to be actively exploited, r2p may accelerate remediation, mitigation and disclosure activities as appropriate.
Following remediation or the availability of appropriate mitigations, r2p may publish information about the vulnerability to help affected users understand the risk and take appropriate action. Publication may be limited where necessary for security, legal, contractual or privacy reasons.
PGP Key File
Fingerprint 02B7 9A42 FA6E D399 3A39 A2E9 4946 B3F4 60B4 B5D2
Download PGP Key FileISO certified
Certification is held by individual legal entities. Each document below is therefore listed under the r2p company to which it applies.
r2p GmbH Flensburg, Germany
Need a document for a tender?
If you need a certificate, scope statement or compliance document that is not listed here, contact r2p and we will provide the appropriate document.