Security Contact
The security of our products and services is our top priority. If you discover a potential security vulnerability or a security-related incident in one of our products, we ask that you report it to us responsibly.
Contact for security reports:
Please include the following information with your report, if possible:
- Affected product and version
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Contact information for follow-up questions
Ci4Rail will acknowledge receipt of the report within 5 business days and provide updates on the status of the investigation.
We request coordinated disclosure and ask reporters not to publicly disclose security vulnerabilities until a fix or workaround is available
Product-Lifecycle
Information regarding maintenance periods, security support, product lifecycles, and end-of-support dates will be published separately for each product in the future. Our goal is to provide our customers with a transparent overview of the availability of security updates and long-term product support.
The relevant information is currently being prepared and will be published in a future update to this website
Security Updates
We are currently working on expanding our security and compliance information in accordance with the requirements of the EU Cyber Resilience Act (CRA). Product-specific information on security updates, known vulnerabilities, and security advisories will be provided on a product-by-product basis going forward.
This information will be added in stages and will be available in time for the relevant regulatory requirements to take effect.
Declaration of Conformity
Product-specific declarations of conformity and regulatory documentation will be made available in a central download section in the future.
These documents are provided in accordance with applicable legal requirements and are continuously expanded as part of our ongoing compliance activities.
