tdmsystems
X
Login / Register
Product Finder

We will help you!

Find the right TDM solution for your manufacture!

TDM ClassiX

On-premise software with a high level of functionality, integration capability, and adaptability.

More information

TDM Global Line

Software on-premise solution with numerous modules for medium to large manufactures.

More information

Free online demo

Request now

Follow us

           

Product Finder

We will help you!

Find the right TDM solution for your manufacture!

TDM ClassiX

On-premise software with a high level of functionality, integration capability, and adaptability.

More information

TDM Global Line

Software on-premise solution with numerous modules for medium to large manufactures.

More information

Free online demo

Request now

Report a Security Vulnerability

TDM Systems GmbH is part of Sandvik. We take the security of our products seriously, and we welcome reports from customers, partners, and security researchers. If you believe you have discovered a security vulnerability in a TDM Systems product or service, please report it to us before disclosing it publicly. We will work with you to confirm and address the issue.

Email: tdm.security@tdmsystems.com – this is our single point of contact for vulnerability reports and the fastest way to reach us. You can also use the form at the bottom of this page.

What to Include

The more detail you can provide, the faster we can confirm and address the issue. Where possible, please include:

  • The affected product or component and its version
  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue, including any preconditions
  • Whether you have any indication that the vulnerability is being actively exploited
  • How you would like to be credited, if at all

Please do not attach working exploit code to the form. If you need to share files or other evidence, please email them to tdm.security@tdmsystems.com instead.

Scope

Security vulnerabilities affecting TDM Systems products, including:

  • TDM Classics
  • TDM Global Line
  • TDMstoreasy
  • TDM appCom
  • TDM iCut
  • TDM WebCatalog
  • All related interfaces

Reports concerning third-party dependencies are welcome and will be forwarded to the relevant upstream project where appropriate.

Out of Scope

  • Third-party products, services, or infrastructure that TDM Systems does not operate or develop
  • Volumetric denial-of-service testing
  • Social engineering or phishing attacks against TDM Systems employees, customers, or partners
  • Findings from automated scanners with no demonstrated security impact
  • Missing security hardening headers or configuration preferences with no exploitable security consequence

How Reports Are Handled

After intake, each report is processed through a consistent vulnerability management workflow:

  • Receive – the report is logged and tagged as a security issue.
  • Review – we assess applicability (whether TDM Systems is affected) and verifiability (whether the issue can be reproduced).
  • Assess – we classify severity (CVSS), evaluate impact and exploitability, and determine remediation priority.
  • Address – we remediate the issue, verify the fix, and coordinate disclosure timing.
  • Close and Learn – we confirm closure and record lessons learned.

If a report concerns a third-party component, we coordinate with the relevant upstream maintainer in parallel with our own remediation planning.

Our Commitment

Stage

Target

Acknowledge receipt

Within 3 business days

Initial assessment & severity (CVSS)

Within 10 business days

Status updates

At least every 2 weeks until resolution

Fix & coordinated disclosure

Timeline agreed with the reporter, prioritized by severity

Once a security update is available, we share information about the resolved vulnerability with affected customers, including a description of the vulnerability, the affected products and versions, the impact, and any actions required.

Safe Harbor

We will not pursue or support legal action against anyone who, in good faith:

  • Makes a reasonable effort to report a vulnerability through the channel above
  • Avoids privacy violations, data destruction, and service degradation
  • Does not access or modify data beyond the minimum necessary to demonstrate the issue

Activity conducted consistently with this policy is considered authorized. If in doubt, please contact us at tdm.security@tdmsystems.com before proceeding.

Please also give us reasonable time to investigate and remediate the issue before disclosing it publicly, and coordinate the timing of any public disclosure with us.

Supported Versions and Updates

Security updates are provided for supported releases during the applicable product support period.

Cloud deployments receive security updates automatically as part of our managed service. For on-premises deployments, we make security updates available together with a clear description of their security relevance.

We Do Not Operate a Bug Bounty

We do not currently offer monetary rewards for vulnerability reports. We are happy to credit reporters who wish to be named.

Not a Security Issue?

For product questions, bugs without a security impact, or support requests, please contact support@tdmsystems.com or use your usual support channel – these channels will reach the appropriate team faster.

Our Security Program

Third-party penetration tests are performed on request and periodically, based on the OWASP Top 10 and OWASP Desktop App Security Verification Standard (DASVS). Automated vulnerability scanning runs as part of our CI/CD pipeline on each deployment.

Our security activities are aligned with the requirements of the EU Cyber Resilience Act (CRA) and support our ongoing vulnerability management and security testing processes.

Submit a Report

You can also email tdm.security@tdmsystems.com directly.

Name and email are optional – you may leave them blank to report anonymously.

Form for Reporting Security Vulnerabilities

I have read and understood the Privacy Policy. I agree that my contact information and any inquiries I submit will be stored.

Read the privacy policy