Information Security
Report security vulnerabilities and information security incidents
On this page, you can report security vulnerabilities in X2E products and IT systems, as well as other information security incidents. You can use our security form or contact us directly by email. Reports can be submitted confidentially and, if desired, anonymously.
Important Information
FAQ on Reporting Security Vulnerabilities
Here you will find answers to the most important questions about reporting security vulnerabilities and information security incidents to X2E. Learn which reporting channels are available, what information is helpful for our assessment, and how we handle your report.
What can I report through this page?
You can report potential security vulnerabilities in X2E products and services, on our website, or within our IT infrastructure. The form can also be used to report other information security incidents.
If you are unsure which category applies, please select “Other Information Security Incidents”. We will classify your report internally and forward it to the appropriate team.
How can I report a security vulnerability or security incident?
You can use our security reporting form or contact us by email:
Product Vulnerabilities: psirt@x2e.de
Website, IT Infrastructure, and Information Security: csirt@x2e.de
If you are unsure which contact is responsible, you can use either reporting channel. Your report will be routed internally to the appropriate team.
Can I submit my report anonymously?
Yes. Providing your name, email address, and other contact details is optional. You can submit the security reporting form anonymously.
However, without a way to contact you, we cannot ask follow-up questions or keep you informed about the status of your report. This may limit our ability to investigate, particularly in complex cases. If possible, we recommend providing a secure means of contact.
What information should I include in my report?
Please provide all information necessary for the investigation, but do not include any unnecessary personal data, login credentials, or data relating to uninvolved third parties.
Where possible, please provide:
- the affected product, service, or system;
- the affected version and configuration;
- as detailed a description of the vulnerability as possible;
- the potential impact;
- clear steps to reproduce the issue;
- any known protective or mitigation measures;
- your contact details, if you would like us to be able to contact you with follow-up questions.
Even incomplete information may be relevant to resolving the issue. We appreciate every report.
How can I securely submit confidential information and files?
The security reporting form is encrypted via HTTPS during transmission. Please remove any confidential or personal information that is not required.
For particularly sensitive information, you can send us an OpenPGP-encrypted and digitally signed email. The public keys and their corresponding fingerprints are available on this page.
Where can I find X2E GmbH’s CVD Policy?
You can find X2E GmbH’s CVD Policy here: Coordinated Vulnerability Disclosure Policy
Report Security Vulnerabilities
How to contact us if you would like to report a security vulnerability
You can submit your report using our security reporting form or directly by email. The form also allows anonymous reports; for confidential information sent by email, an encrypted communication option is available.
Contact Form
Meldung per E-Mail
Security Vulnerabilities in
X2E Products and Services
E-Mail: psirt@x2e.de
OpenPGP-Key: psirt-x2e-de.asc
Information Security
and X2E Infrastructure
E-Mail: csirt@x2e.de
OpenPGP-Key: csirt-x2e-se.asc
