Product Security

Cybersecurity is an integral part of the entire plant for M.A.i GmbH & Co. KG. We are committed to responsibly handling security vulnerabilities in our products and have established the M.A.i Product Security Incident Response Team (PSIRT) for this purpose. It serves as the central point of contact for reporting and analyzing cybersecurity vulnerabilities and incidents.

M.A.i places great importance on the early and effective remediation of security vulnerabilities, as well as on transparent and coordinated handling of reported incidents. Every incoming report is treated confidentially.

To enable us to process your report quickly, please send us at least the following information to PSIRT@m-a-i.de:

  • First and last name and phone number of the reporter, email address of the contact person
  • Unique plant/system number
  • Technical description of the vulnerability and a brief summary of the problem
  • Affected product within the plant, including firmware or software version
  • Assessment of the potential impact
  • Steps to reproduce (e.g. proof of concept, network traces)
  • Information on whether this vulnerability has already been disclosed

We will confirm receipt of your report within three to a maximum of five business days. If we have questions or require further information, we will contact the person you provided.

If possible, please use email encryption and signing when submitting your information to help ensure message integrity.

After internal review and assessment of the reported vulnerability, we will inform you of the next steps, such as the planned timeframe for remediation.

M.A.i does not participate in a bug bounty program. Furthermore, a non-disclosure agreement between the parties is not required for the disclosure of the vulnerability.

For technical issues with the plant that fall outside this scope, please contact our service department by email or phone as usual.