Security

Camtek GmbH develops CAD/CAM software for industrial manufacturing. We take reports of potential security vulnerabilities in PEPS and OPTICAM seriously and handle them as a priority. This page explains how to report a vulnerability to us, what you can expect from us, and which security advisories we have published.

 

Reporting a vulnerability

Please send your report to security@camtek.de. This address is dedicated to security matters and reaches the responsible team directly.

You can also reach us by phone at +49 7151 979202, Monday to Friday from 8:00 to 12:00 and from 13:00 to 17:00 (CET/CEST). For an initial report we prefer email, as it allows the details to be documented in full.

 

Information that helps us

The more precise your report, the faster we can assess and remediate. The following is helpful:

  • the affected product and version number, and the operating system used
  • a description of the vulnerability and its potential impact
  • reproducible steps, ideally with a sample file or screenshots
  • whether the vulnerability has already been published or reported to third parties
  • a means of contacting you for follow-up questions
  • whether you would like to be credited by name in a later publication

 

What you can expect from us

  • We confirm receipt of your report within three working days.
  • We assess the issue and share our technical evaluation with you once the assessment is complete.
  • We keep you informed about further progress and notify you as soon as a fix is available.
  • On request, we will credit you as the finder when the security advisory is published.
  • We do not pass your personal data on to third parties without your consent.

 

Coordinated disclosure

We ask you not to publish details of a reported vulnerability until a fix is available and our customers have had the opportunity to install it. In return, we work promptly on a solution and agree the timing of publication with you. If the vulnerability concerns a component supplied by another manufacturer, we forward your report to them and inform you accordingly.

 

Our commitment to reporters

If you investigate a vulnerability in good faith and observe the following rules, Camtek GmbH will not take legal action against you:

  • You do not access data belonging to others, and you do not modify or delete data.
  • You do not disrupt operations, in particular through no overload or denial-of-service attempts.
  • You limit your investigation to what is necessary to demonstrate the issue.
  • You publish details only after coordinating with us.
  • You comply with applicable law.

 

What is not handled through this channel

For general support enquiries about our products, please contact our support team as usual via Support & Service. This page relates exclusively to security matters concerning products of Camtek GmbH; we are not responsible for our customers’ own systems.

 

Published security advisories

We deliver security-relevant corrections through the current installation package, and outside the monthly cycle where the urgency requires it. We publish details only once a fix is available.

There are currently no published security advisories.