{"id":19516,"date":"2026-08-05T13:34:13","date_gmt":"2026-08-05T13:34:13","guid":{"rendered":"https:\/\/www.tadano.com\/espana-y-portugal\/software-update-cybersecurity\/vulnerability-disclosure-policy\/"},"modified":"2026-08-05T13:34:28","modified_gmt":"2026-08-05T13:34:28","slug":"vulnerability-disclosure-policy","status":"publish","type":"page","link":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/software-update-cybersecurity\/vulnerability-disclosure-policy\/","title":{"rendered":"Vulnerability Disclosure Policy"},"content":{"rendered":"\n<p><strong>Tadano Europe Holdings GmbH Vulnerability Disclosure Policy (VDP)<\/strong><\/p>\n\n\n\n<p><strong>Last updated:<\/strong> Date, 05.08.2026<\/p>\n\n\n\n<p><strong>1. Introduction &amp; Purpose<\/strong><\/p>\n\n\n\n<p>The security of our customers\u2019 and users\u2019 data and systems is of the utmost importance to Tadano Europe Holdings GmbH. We are constantly committed to protecting our systems against security threats. Despite our efforts, vulnerabilities may arise.<\/p>\n\n\n\n<p>This Vulnerability Disclosure Policy (VDP) is intended to provide security researchers and the public with a clear framework for responsibly reporting potential security vulnerabilities in our products, services and infrastructure. We believe that collaborating with the security community helps us to make our systems more secure and better protect our users.<\/p>\n\n\n\n<p><strong>2. Scope<\/strong><\/p>\n\n\n\n<p>This policy applies to all publicly accessible systems, websites, applications and APIs owned, operated and managed by Tadano Europe Holdings GmbH.<\/p>\n\n\n\n<p><strong>What is included within the scope?<\/strong><\/p>\n\n\n\n<p>\u00b7 All web applications and websites operated and controlled by Tadano Europe Holdings GmbH.<\/p>\n\n\n\n<p>\u00b7 All products (cranes, aerial work platforms, spare parts, retrofit kits, etc.) of Tadano Europe Holdings GmbH.<\/p>\n\n\n\n<p>\u00b7 APIs provided by Tadano Europe Holdings GmbH.<\/p>\n\n\n\n<p>\u00b7 Infrastructure managed directly by Tadano Europe Holdings GmbH.<\/p>\n\n\n\n<p><strong>What is <em>not<\/em> included within the scope (Out of Scope)?<\/strong><\/p>\n\n\n\n<p>The following activities and types of vulnerabilities are expressly excluded from this policy and should not be reported:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Physical attacks on offices or data centres.<\/li>\n\n\n\n<li>Social engineering (e.g. phishing, vishing, smishing) targeting our staff or users.<\/li>\n<\/ul>\n\n\n\n<p>\u00b7 Vulnerabilities in third-party applications or services not directly controlled by Tadano Europe Holdings GmbH (e.g. a vulnerability in a cloud provider we use or a social media network that does not belong to us).<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Minor configuration errors or information leaks that do not pose an immediate threat (e.g. software version numbers that are publicly available without known exploits).<\/li>\n\n\n\n<li>Inappropriate rate-limiting issues (e.g. on login forms), unless they lead to a demonstrable, critical vulnerability (e.g. account takeover).<\/li>\n\n\n\n<li>Information that is publicly available and does not constitute a direct vulnerability.<\/li>\n<\/ul>\n\n\n\n<p><strong>3. How to report a security vulnerability<\/strong><\/p>\n\n\n\n<p>If you have discovered a potential security vulnerability, we ask that you report it responsibly and directly to our Product Security Incident Response Team (PSIRT).<\/p>\n\n\n\n<p><strong>Please send us your report via our contact form<\/strong><\/p>\n\n\n\n<p>You are welcome to provide your email address. This will enable us to contact you if we have any queries or to inform you should further information regarding your report be required. Providing this information is, of course, voluntary.<\/p>\n\n\n\n<p><strong>Your report should contain at least the following information:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Date of discovery<\/li>\n\n\n\n<li>Affected product and version<\/li>\n\n\n\n<li>Type of vulnerability &amp; symptoms<\/li>\n\n\n\n<li>Steps to reproduce (proof of concept)<\/li>\n\n\n\n<li>Security implications<\/li>\n\n\n\n<li>Evidence<strong> of active exploitation \/ known security incidents<\/strong><\/li>\n\n\n\n<li>Information about the attacker (if known)<\/li>\n\n\n\n<li>Suggestions for countermeasures<\/li>\n\n\n\n<li>Optional: Your contact details (email address)<\/li>\n<\/ul>\n\n\n\n<p><strong>4. Our commitments to you<\/strong><\/p>\n\n\n\n<p>If you follow this policy and report a security vulnerability responsibly, we will:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Keep you updated on the status of your report and inform you of the progress of the fix.<\/li>\n\n\n\n<li>Not take any legal action against you or file a complaint with law enforcement agencies if you have acted in good faith and in accordance with this policy.<\/li>\n\n\n\n<li>Work closely with you to understand and rectify the vulnerability.<\/li>\n<\/ul>\n\n\n\n<p><strong>5. Your obligations (rules of engagement)<\/strong><\/p>\n\n\n\n<p>To facilitate constructive cooperation, we ask you to observe the following rules:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>No public disclosure:<\/strong> Do not publish or share the vulnerability or any details of it publicly before we have rectified it or a mutually agreed disclosure has been arranged.<\/li>\n\n\n\n<li><strong>Minimal impact:<\/strong> Limit your testing to the minimum necessary to confirm the vulnerability. Do not cause any damage, disrupt the service, delete or alter any data, or infringe on the privacy of other users.<\/li>\n\n\n\n<li><strong>No escalation:<\/strong> Do not attempt to exploit the vulnerability beyond what is necessary for verification. This includes gaining root access, exfiltrating large amounts of data, or exploiting the vulnerability to access other systems.<\/li>\n\n\n\n<li><strong>Avoiding data access:<\/strong> If you inadvertently come across personal or sensitive data, stop your testing immediately, do not make any copies of the data, and report this straight away.<\/li>\n\n\n\n<li><strong>No illegal activities:<\/strong> Do not carry out any activities that contravene applicable laws.<\/li>\n\n\n\n<li><strong>Acting in good faith:<\/strong> We expect you to act in good faith and with the aim of making our systems more secure.<\/li>\n<\/ul>\n\n\n\n<p><strong>6. Legal Safe Harbour<\/strong><\/p>\n\n\n\n<p>We want you to feel confident when reporting security vulnerabilities to us. Provided you comply with this policy and all the obligations set out herein, we will not take legal action against you, will not participate in any prosecution, and will not report you to law enforcement authorities in relation to the security research activities you carry out.<\/p>\n\n\n\n<p>However, this assurance only applies if you:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Comply with all the points in this policy.<\/li>\n\n\n\n<li>Act in good faith and do not cause any damage or misuse any data.<\/li>\n\n\n\n<li>Report the vulnerability in accordance with this policy.<\/li>\n<\/ul>\n\n\n\n<p><strong>7. Changes to this policy<\/strong><\/p>\n\n\n\n<p>This policy may be updated from time to time without prior notice. We recommend that you check this page regularly for any changes.<\/p>\n\n\n\n<p><strong>8. Contact<\/strong><\/p>\n\n\n\n<p>Please use our <a href=\"https:\/\/www.tadano.com\/espana-y-portugal\/en\/software-update-cybersecurity\/\" data-type=\"page\" data-id=\"24213\">contact form<\/a> to submit security reports.<\/p>\n\n\n\n<p>Thank you very much for your efforts in helping us to make our products and systems more secure!<\/p>\n\n\n\n<p><strong>Kind regards,<\/strong><\/p>\n\n\n\n<p><strong>The PSIRT at Tadano Europe Holdings GmbH<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tadano Europe Holdings GmbH Vulnerability Disclosure Policy (VDP) Last updated: Date, 05.08.2026 1. Introduction &amp; Purpose The security of our customers\u2019 and users\u2019 data and systems is of the utmost importance to Tadano Europe Holdings GmbH. We are constantly committed to protecting our systems against security threats. Despite our efforts, vulnerabilities may arise. This Vulnerability [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"parent":17533,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-19516","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Vulnerability Disclosure Policy - Spain &amp; Portugal<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.tadano.com\/espana-y-portugal\/en\/software-update-cybersecurity\/vulnerability-disclosure-policy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Vulnerability Disclosure Policy - Spain &amp; Portugal\" \/>\n<meta property=\"og:description\" content=\"Tadano Europe Holdings GmbH Vulnerability Disclosure Policy (VDP) Last updated: Date, 05.08.2026 1. Introduction &amp; Purpose The security of our customers\u2019 and users\u2019 data and systems is of the utmost importance to Tadano Europe Holdings GmbH. We are constantly committed to protecting our systems against security threats. Despite our efforts, vulnerabilities may arise. This Vulnerability [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.tadano.com\/espana-y-portugal\/en\/software-update-cybersecurity\/vulnerability-disclosure-policy\/\" \/>\n<meta property=\"og:site_name\" content=\"Spain &amp; Portugal\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-05T13:34:28+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.tadano.com\\\/espana-y-portugal\\\/en\\\/software-update-cybersecurity\\\/vulnerability-disclosure-policy\\\/\",\"url\":\"https:\\\/\\\/www.tadano.com\\\/espana-y-portugal\\\/en\\\/software-update-cybersecurity\\\/vulnerability-disclosure-policy\\\/\",\"name\":\"Vulnerability Disclosure Policy - Spain &amp; Portugal\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.tadano.com\\\/espana-y-portugal\\\/en\\\/#website\"},\"datePublished\":\"2026-08-05T13:34:13+00:00\",\"dateModified\":\"2026-08-05T13:34:28+00:00\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.tadano.com\\\/espana-y-portugal\\\/en\\\/software-update-cybersecurity\\\/vulnerability-disclosure-policy\\\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.tadano.com\\\/espana-y-portugal\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.tadano.com\\\/espana-y-portugal\\\/en\\\/\",\"name\":\"Spain &amp; Portugal\",\"description\":\"Just another TADANO EUROPE site\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.tadano.com\\\/espana-y-portugal\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Vulnerability Disclosure Policy - Spain &amp; Portugal","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/software-update-cybersecurity\/vulnerability-disclosure-policy\/","og_locale":"en_US","og_type":"article","og_title":"Vulnerability Disclosure Policy - Spain &amp; Portugal","og_description":"Tadano Europe Holdings GmbH Vulnerability Disclosure Policy (VDP) Last updated: Date, 05.08.2026 1. Introduction &amp; Purpose The security of our customers\u2019 and users\u2019 data and systems is of the utmost importance to Tadano Europe Holdings GmbH. We are constantly committed to protecting our systems against security threats. Despite our efforts, vulnerabilities may arise. This Vulnerability [&hellip;]","og_url":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/software-update-cybersecurity\/vulnerability-disclosure-policy\/","og_site_name":"Spain &amp; Portugal","article_modified_time":"2026-08-05T13:34:28+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/software-update-cybersecurity\/vulnerability-disclosure-policy\/","url":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/software-update-cybersecurity\/vulnerability-disclosure-policy\/","name":"Vulnerability Disclosure Policy - Spain &amp; Portugal","isPartOf":{"@id":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/#website"},"datePublished":"2026-08-05T13:34:13+00:00","dateModified":"2026-08-05T13:34:28+00:00","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.tadano.com\/espana-y-portugal\/en\/software-update-cybersecurity\/vulnerability-disclosure-policy\/"]}]},{"@type":"WebSite","@id":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/#website","url":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/","name":"Spain &amp; Portugal","description":"Just another TADANO EUROPE site","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/wp-json\/wp\/v2\/pages\/19516","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/wp-json\/wp\/v2\/comments?post=19516"}],"version-history":[{"count":0,"href":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/wp-json\/wp\/v2\/pages\/19516\/revisions"}],"up":[{"embeddable":true,"href":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/wp-json\/wp\/v2\/pages\/17533"}],"wp:attachment":[{"href":"https:\/\/www.tadano.com\/espana-y-portugal\/en\/wp-json\/wp\/v2\/media?parent=19516"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}