How to Contact Us
Laurin Schmid
Contact
Laurin Schmid
-
Location:
Steinplatz 1
10623 Berlin
Telefax: +49 (0) 30 310078-141 - Email: vdivde-it@vdivde-it.de
- Phone number: +49 (0) 30 310078-0
On site
Other Locations

Berlin
VDI/VDE Innovation + Technik GmbH
Steinplatz 1
10623 Berlin
Germany
vdivde-it@vdivde-it.de +49 (0) 30 310078-0
Mehr Infos
Bonn
VDI/VDE Innovation + Technik GmbH
Dreizehnmorgenweg 36
53175 Bonn
Germany
kontakt@vdivde-it.de +49 (0) 228 39175-22
Mehr Infos
Dresden
VDI/VDE Innovation + Technik GmbH
Kramergasse 2
01067 Dresden
Germany
kontakt@vdivde-it.de +49 (0) 351 486797-10
Mehr Infos
Erfurt
VDI/VDE Innovation + Technik GmbH
Hirschlachufer 1
99084 Erfurt
Germany
kontakt@vdivde-it.de +49 (0)160 142 55 67
Mehr Infos
Hanover
VDI/VDE Innovation + Technik GmbH
Berliner Allee 5
30175 Hanover
Germany
kontakt@vdivde-it.de +49 (0) 30 310078-236
Mehr Infos
Munich
VDI/VDE Innovation + Technik GmbH
Heimeranstr. 37
80339 München
Germany
kontakt@vdivde-it.de +49 (0) 89 5108963-0
Mehr Infos
Stuttgart
VDI/VDE Innovation + Technik GmbH
Marienstr. 23
70178 Stuttgart
Germany
kontakt@vdivde-it.de +49 (0)711 658 355-0
Mehr InfosFeedback
Your opinion is important to us
Feedback
Dear customer,
Do you have any questions about our company? Suggestions, ideas for improvement, praise or criticism? Then please let us know. We look forward to your feedback and will get back to you shortly.
If you are referring to a specific case, please give us the relevant reference (file or grant number, names, dates).
Please contact our quality management.
As part of our environmental management system in accordance with DIN ISO 14001, we strive to improve our environmental performance and reduce the negative impact of our activities on the environment. If you have any questions or suggestions for improvement in this regard, please feel free to address them to our environmental management team at any time.
Thank you!
Note: If you wish to comment on or object to administrative procedures within the time limit, please do NOT use this e-mail, but send a letter or messenger to the contact address specified in the underlying correspondence. The same applies to any other type of communication for which the written form is required by law.
Data protection: We do not pass on your data to third parties. It will only be passed on to the responsible employees for the purpose of processing the content.
Information Security
Information processing plays a key role in carrying out our tasks at VDI/VDE-IT. As a service provider, handling confidential information is part of our daily business.
If you have any comments, suggestions, or questions regarding information security, or if you would like to report vulnerabilities or incidents, we welcome your feedback.
Please feel free to contact our information security team.
Environmental Management
As part of our environmental management system in accordance with DIN ISO 14001, we strive to improve our environmental performance and reduce the negative impact of our activities on the environment. If you have any questions or suggestions for improvement, please feel free to contact the Environmental Management Department at any time.
Here you will find further information on our environmental management and our Certificates.
Administrative Procedures
If you wish to comment on or object to administrative proceedings within the prescribed time limit, please DO NOT use any of these email addresses; instead, contact the address specified in the relevant correspondence by regular mail or courier. The same applies to any other form of communication for which written form is required by law.
Privacy Policy
You can view our privacy policy here.
You can contact our data protection officer at Datenschutz@vdivde-it.de
Thank you very much!
Corruption Prevention
Corruption Prevention and Whistleblower Protection
Integrity and Transparency
VDI/VDE Innovation + Technik GmbH is committed to responsible corporate governance. In our day-to-day operations, we are therefore guided by a mission statement based on integrity and transparency.
To support this, VDI/VDE Innovation + Technik GmbH actively works to prevent corruption. As part of our compliance program, we have established a whistleblower system.
Our Whistleblower System – Available Anytime, Secure, and Confidential
To effectively protect whistleblowers, we offer a state-of-the-art, secure communication platform through which reports can be submitted. Here, you can confidentially report suspected misconduct—particularly in connection with possible corruption or other forms of white-collar crime. You decide for yourself whether to provide your name or remain anonymous.
Setting up a mailbox allows you to receive anonymous updates on the current status of your report and, if necessary, to exchange additional information. The confidentiality of your report is guaranteed at all times.
As of August 8, 2025, reports can only be submitted through the new whistleblower system, EQS Integrity Line.
About the Whistleblower System
Corruption Prevention Contacts
However, you can also contact our internal reporting office directly, which is managed by the corruption prevention liaisons:
VDI/VDE Innovation + Technik GmbH
Abteilung Recht
Steinplatz 1
10623 Berlin
E-Mail: korruptionspraevention@vdivde-it.de
Note
Please note that the whistleblower system should only be used for reports related to the violations described above.
For other inquiries and complaints, please contact the usual points of contact at our office.
Human Rights Due Diligence Obligations
Responsible Corporate Governance
VDI/VDE Innovation + Technik GmbH is committed to responsible corporate governance. In our daily operations, we are guided by a mission statement based on integrity and transparency. Therefore, VDI/VDE Innovation + Technik GmbH opposes human rights violations and environmental damage. The law imposes due diligence obligations on companies, such as conducting a risk analysis, publishing a policy statement on human rights, and, where necessary, implementing preventive and remedial measures.
This report documents the implementation of due diligence obligations for the period from January 1, 2024, to December 31, 2024.
The report on the Supply Chain Due Diligence Act (LkSG) (January 1, 2024–December 31, 2024) will be made publicly available free of charge for a period of at least seven years.
In addition, to supplement our existing compliance program, we have established a whistleblower system for reportable human rights violations and environmental damage.
Vulnerability Disclosure Policy
Motivation
VDI/VDE Innovation + Technik GmbH (VDI/VDE-IT) attaches great importance to the protection of information and the IT security of its systems and applications. Despite careful development, testing and continuous security reviews, vulnerabilities may arise in the web applications we provide (in particular portal solutions provided as part of funding schemes). Systems operated by our contractors are excluded from this policy.
This Vulnerability Disclosure Policy (VDP) establishes a clear framework to enable security researchers and external reporting parties to communicate vulnerabilities responsibly. Our aim is to resolve reported security issues quickly, transparently and in a coordinated manner, whilst at the same time enhancing the security of our services.
Your contribution and rules of conduct
If you discover a vulnerability in a VDI/VDE-IT web application or IT system, please let us know. To enable us to investigate and rectify the vulnerability efficiently, please observe the following rules:
-
- No active exploitation of the vulnerability (no downloading, deleting or altering of data; no disruption to the availability of services and applications).
- Do not disclose information about the vulnerability to third parties prior to official disclosure by VDI/VDE-IT.
- No attacks: No social engineering (e.g. phishing), denial-of-service attacks or physical attacks on systems or staff.
- Adequate documentation: Please provide sufficient information to reproduce and understand the vulnerability. Example: URL, affected function, description, proof of concept, expected behaviour.
- Confidentiality: Please use encrypted communication channels (S/MIME-encrypted email or the upload tool).
Our Commitment
-
- Prompt response: We will acknowledge receipt of your report within five working days.
- Confidentiality: We will treat your report as confidential and will not disclose the reporting person’s personal data to third parties without their express consent, unless we are legally obliged to do so.
- Transparency: We will keep you informed of the progress of the investigation and any planned remedial measures.
- Cooperation: We will consult with you regarding the publication of vulnerability information in order to minimise risks.
- Acknowledgement: With your consent, you (by name or alias) may be named as the discoverer on our ‘Acknowledgement’ page.
- Remediation: We adhere to international recommendations (e.g. ENISA, NIST SP 800-216) and aim to rectify vulnerabilities within 90 days of receiving the report or to provide an appropriate interim solution
- No legal risk from VDI/VDE-IT: Provided you act in accordance with this policy and in a responsible manner, we will not take any legal action ourselves. However, statutory reporting obligations, protective measures in favour of third parties and any rights of third parties remain unaffected.
How to submit a report
Please send your report to:
isb@vdivde-it.de (S/MIME)
Your report should include the following details:
Template for a vulnerability report
| Field | Description |
| Title / Summary | Short, concise description of the vulnerability. |
| Affected Application / Service | Name of the web application or service, or its URL. |
| Description | Technical details, including steps to reproduce, expected vs. actual behavior. If applicable, classify the vulnerability according to the OWASP Top 10 (https://owasp.org/www-project-top-ten). |
| Severity | Severity assessment based on CVSS (optional). |
| Proof of Concept (PoC) | Sample code or step-by-step instructions demonstrating the vulnerability. |
| Impact | Potential damage or risk posed by the vulnerability. |
| Suggested Remediation (optional) | Recommendations or guidance for resolving the vulnerability. |
| Your Contact Information | Name or alias, email address |
| Consent to Acknowledgement (Yes/No) |
Once the report has been received, it will be processed in accordance with our internal CVD process, which is based on the ISO/IEC 30111 (Vulnerability Handling) and ISO/IEC 29147 (Disclosure) standards.
What we do not want: unqualified vulnerabilities.
The following reports do not fall within the scope of this policy:
- Missing security headers (e.g. CSP, HSTS) without concrete exploitability
- Reports from automated scans without technical analysis
- DoS tests, spam, social engineering or brute-force attempts
- Vulnerabilities in third-party systems (e.g. hosting providers, external tools)
- General suggestions for improvement or best practices (e.g. password policies)
Contact
VDI/VDE Innovation + Technik GmbH
Information Security
Steinplatz 1, 10623 Berlin
Email: isb@vdivde-it.de
Website: https://vdivde-it.de/de
Media Inquiries
Please direct press and media inquiries to medien@vdivde-it.de
Phone: +49 (0)30 310078-127
or visit our Media page for more information.
Contact