Tadano Europe Holdings GmbH Vulnerability Disclosure Policy (VDP)

Last updated: Date, 05.08.2026

1. Introduction & Purpose

The security of our customers’ and users’ data and systems is of the utmost importance to Tadano Europe Holdings GmbH. We are constantly committed to protecting our systems against security threats. Despite our efforts, vulnerabilities may arise.

This Vulnerability Disclosure Policy (VDP) is intended to provide security researchers and the public with a clear framework for responsibly reporting potential security vulnerabilities in our products, services and infrastructure. We believe that collaborating with the security community helps us to make our systems more secure and better protect our users.

2. Scope

This policy applies to all publicly accessible systems, websites, applications and APIs owned, operated and managed by Tadano Europe Holdings GmbH.

What is included within the scope?

· All web applications and websites operated and controlled by Tadano Europe Holdings GmbH.

· All products (cranes, aerial work platforms, spare parts, retrofit kits, etc.) of Tadano Europe Holdings GmbH.

· APIs provided by Tadano Europe Holdings GmbH.

· Infrastructure managed directly by Tadano Europe Holdings GmbH.

What is not included within the scope (Out of Scope)?

The following activities and types of vulnerabilities are expressly excluded from this policy and should not be reported:

  • Physical attacks on offices or data centres.
  • Social engineering (e.g. phishing, vishing, smishing) targeting our staff or users.

· Vulnerabilities in third-party applications or services not directly controlled by Tadano Europe Holdings GmbH (e.g. a vulnerability in a cloud provider we use or a social media network that does not belong to us).

  • Minor configuration errors or information leaks that do not pose an immediate threat (e.g. software version numbers that are publicly available without known exploits).
  • Inappropriate rate-limiting issues (e.g. on login forms), unless they lead to a demonstrable, critical vulnerability (e.g. account takeover).
  • Information that is publicly available and does not constitute a direct vulnerability.

3. How to report a security vulnerability

If you have discovered a potential security vulnerability, we ask that you report it responsibly and directly to our Product Security Incident Response Team (PSIRT).

Please send us your report via our contact form

You are welcome to provide your email address. This will enable us to contact you if we have any queries or to inform you should further information regarding your report be required. Providing this information is, of course, voluntary.

Your report should contain at least the following information:

  • Date of discovery
  • Affected product and version
  • Type of vulnerability & symptoms
  • Steps to reproduce (proof of concept)
  • Security implications
  • Evidence of active exploitation / known security incidents
  • Information about the attacker (if known)
  • Suggestions for countermeasures
  • Optional: Your contact details (email address)

4. Our commitments to you

If you follow this policy and report a security vulnerability responsibly, we will:

  • Keep you updated on the status of your report and inform you of the progress of the fix.
  • Not take any legal action against you or file a complaint with law enforcement agencies if you have acted in good faith and in accordance with this policy.
  • Work closely with you to understand and rectify the vulnerability.

5. Your obligations (rules of engagement)

To facilitate constructive cooperation, we ask you to observe the following rules:

  • No public disclosure: Do not publish or share the vulnerability or any details of it publicly before we have rectified it or a mutually agreed disclosure has been arranged.
  • Minimal impact: Limit your testing to the minimum necessary to confirm the vulnerability. Do not cause any damage, disrupt the service, delete or alter any data, or infringe on the privacy of other users.
  • No escalation: Do not attempt to exploit the vulnerability beyond what is necessary for verification. This includes gaining root access, exfiltrating large amounts of data, or exploiting the vulnerability to access other systems.
  • Avoiding data access: If you inadvertently come across personal or sensitive data, stop your testing immediately, do not make any copies of the data, and report this straight away.
  • No illegal activities: Do not carry out any activities that contravene applicable laws.
  • Acting in good faith: We expect you to act in good faith and with the aim of making our systems more secure.

6. Legal Safe Harbour

We want you to feel confident when reporting security vulnerabilities to us. Provided you comply with this policy and all the obligations set out herein, we will not take legal action against you, will not participate in any prosecution, and will not report you to law enforcement authorities in relation to the security research activities you carry out.

However, this assurance only applies if you:

  • Comply with all the points in this policy.
  • Act in good faith and do not cause any damage or misuse any data.
  • Report the vulnerability in accordance with this policy.

7. Changes to this policy

This policy may be updated from time to time without prior notice. We recommend that you check this page regularly for any changes.

8. Contact

Please use our contact form to submit security reports.

Thank you very much for your efforts in helping us to make our products and systems more secure!

Kind regards,

The PSIRT at Tadano Europe Holdings GmbH