Service After sales service for the life of the vehicle. Here you will find our offerings from maintenance to obsolescence management.

Company Discover more about our group of companies, the employees, and the management.

Kiepe Coordinated Vulnerability Disclosure Policy (CVD)

 

1.1 Purpose

Kiepe Electric develops and supplies safety-relevant traction- and control-systems for urban rail vehicles and public transportation operators. Maintaining the cybersecurity and safety of these products throughout their lifecycle is a core responsibility of Kiepe.

The purpose of this Coordinated Vulnerability Disclosure (CVD) Policy is to provide a structured and transparent process for reporting, assessing, coordinating, remediating, and disclosing cybersecurity vulnerabilities affecting Kiepe products, services, and solutions.

This policy defines the responsibilities of Kiepe, the reporting party, and other stakeholders involved in the coordinated handling of vulnerabilities.

The Kiepe Product Security Incident Response Team (PSIRT) is responsible for managing the vulnerability disclosure process.

 

1.2 Scope

This policy applies to cybersecurity vulnerabilities affecting:

  • Kiepe traction systems;
  • Vehicle control and management systems;
  • Communication systems;
  • Diagnostic and maintenance systems;
  • Software, firmware, hardware, and supporting services provided by Kiepe;
  • Products currently supported by Kiepe.

 

The policy covers vulnerabilities discovered by:

  • Stakeholders and service partners;
  • Security researchers;
  • Suppliers and partners;

     

1.3 Reporting a Vulnerability to Kiepe PSIRT

Kiepe encourages responsible reporting of cybersecurity vulnerabilities.

Reports can be submitted through one of the following channels:

  • Email

 

Contact:

Email: psirtkiepe-group.com

Security.txt: https://kiepe-group.com/.well-known/security.txt

PGP Key: https://kiepe-group.com/pgp-keys/kiepe-psirt-public.asc

Website: https://www.kiepe-group.com

 

Accessibility

Kiepe aims to make vulnerability reporting accessible to all stakeholders. Individuals requiring assistance in submitting reports may contact Kiepe through alternative customer support channels referenced on the Kiepe website.

 

1.4 Secure Communication

Because vulnerability reports frequently contain sensitive security information, Kiepe strongly recommends the use of encrypted communications.

Kiepe supports encrypted email communication through its RFC 9116 compliant security.txt file:

kiepe-group.com/.well-known/security.txt

The Kiepe PSIRT public PGP key is available at:

kiepe-group.com/pgp-keys/kiepe-psirt-public.asc

Reporters are encouraged to encrypt vulnerability reports using this key whenever possible.

 

1.5 Required information from the Reporter

To enable efficient investigation and analysis, Kiepe requests the following information where applicable:

  • Reporter contact details (not required in case of anonym reporting);
  • Product name and version;
  • System configuration information;
  • Detailed description of the vulnerability;
  • Potential security impact on upper system / vehicle level
  • Information how to reproduce the issue;
  • Information regarding known exploitation;

Reports containing incomplete information will still be accepted and reviewed.

 

1.6 Communication to Reporter

Kiepe is committed to maintaining communication with the reporter throughout the vulnerability handling process.

The PSIRT will provide status updates at mutually agreed intervals and will communicate:

  • Validation results;
  • Planned mitigation activities;
  • Expected disclosure timelines;
  • Publication coordination activities.

Response timelines may vary depending on vulnerability complexity, operational impact, and safety considerations

 

1.7 Disclosure Strategy of Vulnerabilities

Kiepe follows the principles of Coordinated Vulnerability Disclosure.

To reduce the risk of malicious exploitation:

  • Vulnerability information should remain confidential during investigation and remediation.
  • Public disclosure should be deferred until appropriate mitigations or fixes are available.
  • Disclosure timelines may be adjusted based on risk, complexity, and stakeholder requirements.

Kiepe seeks to balance transparency with the need to protect operators, passengers, public infrastructure, and affected systems.

 

1.8 Publication

In any case of vulnerabilities with risk the Kiepe PSIRT provides guidance on disclosing the vulnerability: The PSIRT coordinates reporting and publishes information by Kiepe security advisories to the relevant stakeholders about identifying and remediating the vulnerability.

The Kiepe security advisories provide detailed information about the vulnerability for Kiepe products and services, which require a product upgrade or customer actions.

Advisories might be distributed in batches with an interim and final status:

This could be the case for temporary remediations, which can be applied by the stakeholder to reduce the risk, because the design change of the product (e.g. software patch) cannot be provided just in time.

In interim status analysis results, temporary remediations and timing information release dates for the product update are defined.

In the final status the remediation is completed.

 

In case of vulnerabilities, which have caused a severe incident, or in case of actively exploited vulnerabilities affecting Kiepe products or products supported by Kiepe or critical services, Kiepe will report those to the appropriate competent authority ENISA defined by the European Regulation 2024/2847.

 

1.9 Policy Compliance

All vulnerability reports received through the channels described in this policy are handled by the Kiepe PSIRT according to the organization's Vulnerability Handling Process.

The PSIRT maintains records of reported vulnerabilities, investigation activities, remediation actions, communications, and disclosure decisions.