Skip to content

Cybersecurityđź”—

At MVTec, we prioritize product quality and customer benefit. Our software is developed by highly skilled engineers at our Munich headquarters, following industry best practices and strict guidelines.

We are committed to ensuring our software:

  • Meets recognized industry standards and regulatory requirements.
  • Is designed and tested to be free from known vulnerabilities and backdoors.
  • Is continuously monitored and updated to address emerging security threats.
  • Includes documentation that transparently lists third‑party components and dependencies.

All transmitted data complies with the General Data Protection Regulation (GDPR) and our data privacy guidelines. Under no circumstances is any personal data transmitted to MVTec.

Relevant changes are listed in the Release Notes.

Security contactđź”—

For any security-related questions or concerns, please contact us at security@mvtec.com. Your request will be handled with care and discretion.

For more information and contact options, please visit the MVTec homepage: www.mvtec.com/cybersecurity.

Verifying the softwaređź”—

When installing MVTec software (including the Software Manager) from the MVTec website, the integrity of downloaded packages is verified automatically.
On Windows, we recommend also confirming the digital signature of the SOM executable.

To verify the signature on Windows:

  1. Open the downloaded folder containing the som.exe.
  2. Open the context menu of som.exe and select Properties.
  3. Select the Digital Signatures tab.
  4. Double-click a “MVTec Software GmbH” entry in the list.
    ⤷ Only continue using SOM if the dialog shows “This signature is OK.”

You can additionally verify the checksum for downloaded files. Checksums for products are available on the product download pages https://www.mvtec.com/downloads/.

To verify the checksum of a downloaded file, you can use the following command:

sha512sum -c <downloaded checksum file>

certutil -hashfile <downloaded installation file> sha512
Verify that the displayed hash matches the value in the downloaded checksum file.

MVTec Software Manager backend and frontend communicationđź”—

The MVTec Software Manager can be separated into two parts: backend and frontend. The frontend runs in the browser and communicates with the backend over the default port 8188, which the backend binds on “localhost”. The hostname and the port can be configured by the user.

Communication is secured using a cookie. The backend accepts and executes requests only when the request contains the correct cookie. The backend issues this cookie after startup by generating a token. When SOM opens the frontend, the token is provided to the frontend via URL query parameters. The token can also be obtained or copied via the tray icon. As an alternative, the token mechanism can be replaced by a fixed password configured by the user in SOM.

In addition, the frontend fetches the RSS feed from mvtec.com. On startup, the backend synchronizes available products by downloading product description files from packages.mvtec.com.

Product signature integrityđź”—

The Software Manager installs only products originating from MVTec. All product description files defining available products are signed by MVTec. If a valid signature is missing or cannot be verified, SOM does not accept those files.

To ensure package integrity, SOM relies on checksums that are provided in the signed product description files. After downloading a package, SOM verifies that the package contents match the expected checksum. If it does not match, SOM refuses to install the package.

Admin rights in SOMđź”—

SOM is designed to be run by a normal user, not by an administrator. If an individual step requires elevated privileges, SOM requests admin rights only for that specific step and then returns them immediately after the step is completed.