Information Security Reporting

The security of all assets, including but not limited to Porsche vehicles, digital services, and accessories, are crucial for Porsche. Despite our rigorous development, manufacturing, and testing processes, vulnerabilities may exist in specific instances. We are committed to identifying and addressing all relevant vulnerabilities and welcome collaboration with individuals who report them to us. If you have any information about a vulnerability in any Porsche asset, including its services, vehicles, digital domains, or accessories, please inform us.

We kindly request that you refrain from disclosing any vulnerabilities until we have had the opportunity to analyze them and, if necessary, implement appropriate measures.

Please send your information via encrypted e-mail to: security@porsche.de

To encrypt, please use the certificate provided on this website. The corresponding CA certificates can be downloaded at the menu item "Volkswagen PKI CA Certificates" on https://certdist.volkswagen.de.

Our principles

What is important to us:

Comply with applicable laws, regulations and other statutory provisions as well as with contractual provisions, including licensing or consent requirements.

Do not harm anyone.

Avoid impact on the privacy of third parties.

Please send us your information in German or in English.

Please provide a contact for further queries.

Provide sufficient information for us to reproduce and analyze the issue, including:
– Time when the vulnerability was discovered.
– All available information on the model and components, part numbers, chassis numbers and software versions.
– Prerequisites and general conditions that must be fulfilled in order to be able to exploit the vulnerability.
– Set up configuration and modification of the vehicle, digital service or accessory and if possible a proof of concept.

Please allow us to disclose the vulnerability in a coordinated manner, in particular by refraining from disclosing vulnerability details to third parties before the end of a mutually agreed timeframe.

Scope of application

All vehicles and products of Porsche and Porsche-related brands, including internet facing services, applications and domains.

Non-qualified vulnerabilities

The following vulnerabilities are not within the scope of this policy:

Results originated from social engineering (e.g. phishing, vishing).

User experience issues, spelling and grammar errors.

Scroll to the page top.