Additional Information

Whistleblower System

Complying with statutory regulations and internal rules, and the principles laid down in our Code of Conduct and the Code of Conduct for Business Partners, has top priority at Bentley Motors Ltd. The success of our company is based on Integrity and Compliance. To meet these standards, it is important to learn of potential employee or supplier misconduct and to put a stop to it. Therefore, we have entrusted the Audi Investigation Office to operate an independent, impartial and confidential Whistleblower System on our behalf.

 

A key pillar of our Whistleblower System is the principle of procedural fairness. It also guarantees the greatest possible protection for whistleblowers, persons implicated and employees contributing to the investigation of reported misconduct.

 

This also includes offering opportunities for anonymous reporting and communication. We assure not to perform any steps in order to identify anonymous whistleblowers, who do not misuse our Whistleblower System. Retaliation of whistleblowers and all persons who contribute to investigations at Bentley will not be tolerated. Persons implicated are presumed innocent until the violation is proven. Investigations will be conducted with the utmost confidentiality. The information will be processed in a fair, fast and protected process.

The qualified and experienced colleagues at the Investigation Office examine every report for potential misconduct by a Bentley employee thoroughly and follow it up systematically. First, you will get a confirmation of receipt. The Investigation Office then assesses your report. This includes gathering facts particularly from the whistleblower. Only if this initial evaluation shows grounds for suspicion of a violation an investigation by a dedicated Investigating Unit will be started. Afterwards, the results of the investigation will be assessed by the Investigation Office and appropriate measures will be recommended. Information about the status* and the outcome of the procedure will be given to you without undue delay.

 

Potential violations of the Code of Conduct for Business Partners by suppliers, including serious risks and violations of human rights and environment by direct and indirect suppliers, can also be reported to the Investigation Office - as well as reports requiring otherwise immediate action. The Investigation Office will inform the responsible departments, who will process the issue accordingly. This particularly includes taking the necessary measures to minimise or end violations and/or risks.

 

 * The processing time varies depending on the subject of the procedure.

 

More information on the respective procedural principles can be found here.

For complaints or feedback about vehicles and services of Bentley or our business partners (e.g. car dealerships, workshops), please contact:

 

 

https://www.bentleymotors.com/en/pages/contact-us.html

 

Please understand that we will not be able to forward your request or take any action for reasons of responsibility.

The Whistleblower System offers various channels to report potential misconduct by Bentley employees, violations of the Code of Conduct for Business Partners violations of the Code of Conduct for Business Partners or serious risks and violations of human rights and environment in our Supply Chain. However, this does not affect your statutory right to contact designated authorities.

 

Please read the Audi data privacy statement and the Audi statement of consent before getting in touch.

 

Use this link to find out more information about the Whistleblower System: https://cdn.bentleymotors.com/downloads/corporate/2025-08-04_Basic_Information_WBS_Communication_v2.pdf

The Investigation Office of Bentley can be reached via E-mail (in any language): 

 

whistleblower-office@audi.de

 

For customer complaints, please contact the channels listed under "A complaint about products or services to our customer service".

AUDI AG


Postal address: 

Audi AG Whistleblower System

D-85045 Ingolstadt, Germany

 

In person:    

Audi Investigation Office

AUDI AG

I/FG-H

85045 Ingolstadt, Germany

 

Appointments may be arranged in advance via whistleblower-office@audi.de

Bentley has appointed external lawyers to act as Ombudspersons. They advise on the Whistleblower System or ensure that reports from whistleblowers are forwarded anonymously to the Audi Investigation Office if desired.

 

If you want to get in contact with the Ombudsperson you can find their contact details here: https://www.ombudsmen-of-volkswagen.com/

You have the option of using a web-based communication platform SpeakUP* to contact the Investigation Office in more than 65 languages. This system is confidential and technically secured and allows you to submit reports anonymously.

 

Use this link to access the online reporting channel: https://goto.speakup.report/audi 

 

Use this link to access detailed instructions on how to make reports online, by app or by phone: https://cdn.bentleymotors.com/downloads/corporate/2021-11-01 SpeakUp - How To Report Guide.pdf

Find out more about how to use the speak up online reporting in this short video.

Main QR Code 1.png

You can leave a voice message by phone 24 hours a day, 7 days a week.

 

After entering the phone number (specific to the country you are in), you will be prompted to enter the organisation code. Then, you can submit your report as a voice recording. Only a written transcript will be received by the Audi Investigation Office. Dial back in to listen to the reply or further questions by the team. 

 

Select a phone number from the below list for your country or region (UK: 0800 022 4118) and have the organisation code 122237 ready. 

 

Access the full list of phone numbers by clicking here.

You can also download the Speak Up App “SpeakUp “ by People Intouch (personal devices only) to access the secure reporting system. Through this app, you can submit your report in writing or leave a voice message (also anonymously). Log back in to see our team's reply or answer further questions. Find out more about how to use the speak up app in this short video.

Once you have downloaded the app, you will need the organisation code 122237

Main QR Code 2.png

A report should be as specific as possible. Use the following questions to help:

 

Who? is affected? who might be responsible? has is happened before?

What? happened? what damage has occurred?

When? did the incident occur? is it still ongoing? are there witnesses?

Why? was the potential violation committed? (if known), why do you think this a violation? e.g. which law/ policy has been allegedly violated?

Where? did the potential violation take place?

How? can the potential violation be substantiated? can you provide any evidence?

Questions or suggestions for improvement concerning the Whistleblower System can also be addressed to the Audi Investigation Office. 

 

If you have been interviewed in terms of an investigation, you have the possibility to give feedback to the Ombudsperson as independent body.

 

Furthermore, our local Integrity & Compliance Officer can also be addressed in all matters of the Whistleblower System via compliance@bentley.co.uk.

Gender Pay Reports

Modern Slavery Statements

Cyber Security

Preserving the safety, security and quality of our products is an important issue to us. Indications from security experts are therefore of utmost importance to us. If you find a potential vulnerability in one of our products, please mail your results to vehicle.vulnerabilities@bentley.co.uk. Please pay attention to the scope and the disqualifying and qualifying vulnerabilities.

- Please use only the designated communication channel to report information concerning vulnerabilities.

 

- Please send information only in English.

 

- Provide enough details for us to reproduce the vulnerability.

- Tell us the date you found the vulnerability

 

- In the case of a vehicle vulnerability please send us all available information about the model, VIN (Vehicle Identification Number), the component(s), part number(s) and software version.

 

- Describe the prerequisites that need to be met to exploit the vulnerability.

 

- Describe the tested system state and if possible, provide Proof-of-Concept code.

 

- Don’t send findings from automated scanning tools only.

- Any independent activity in context with our products is at your own risk.

 

- Always comply with relevant laws.

 

- If you want to examine one of our products or vehicles, only use a vehicle in your ownership or one, for that you have the permission of the owner to examine it.

 

- Do not access or manipulate data if you do not own it or if you do not have the explicit permission of the owner.

 

- Do not start attacks leading to denial-of-service attacks and overall avoid high network load. If you think our servers have a specific problem in dealing with high data load, you are welcome to report it to the designated communication channel and we will reproduce your findings in a non-productive environment.

 

- All activities with criminal relevance are prohibited in any form.

 

- Please consider that it is possible to infringe the rights of third parties with reverse engineering. This can lead to legal consequences.

 

- Do not conduct activities that could harm you or others.

 

- Never endanger road safety and do not perform tests on public roads or places, but only at a secured place with a non-driving vehicle.

 

Usually we will answer your mail within 2-3 business days and inform you about the further procedure. Please note that vehicles are subject to safety and legal regulations. Therefore it can be quite a long process to resolve vulnerabilities in vehicles e.g. because of necessary validation. So we kindly ask you to give us time (Responsible Disclosure).

IT systems

 

All hosts in the ownership of Bentley Motors Apps

 

All apps, that are published by Bentley Motors, e.g. My Bentley

 

Vehicles that were sold under the brand Bentley Motors

 

Equipment that was sold under the brand Bentley Motors

Web pages of Bentley partners – occasionally Bentley partner use a subdomain of .bentleymotors as address for their web site. Bentley Motors has no control over those web pages. Please contact the corresponding dealer if you find a vulnerability there.

Vulnerabilities outside the scope

 

Denial-of-service attack (DoS / DDoS)

 

Brute-force attack

 

Social engineering

 

Vulnerabilities without an impact on safety or security (Vulnerabilities must have a security or safety impact in order to be considered)

 

URL forwarding

 

Reports, generated by automatic scan tools

 

Missing TLS communication

 

Expired TLS certificates

Physical destruction of locks, anti-theft devices etc.

 

Gaining access to a vehicle by physical destruction

 

Use of valid diagnostic functions

 

Denial-of-service attacks on ECUs or bus systems via flooding attacks

Injection

 

Broken Authentication

 

Cross-Site-Scripting (XSS)

 

Insecure Direct Object References

 

Security Misconfiguration

 

Sensitive Data Exposure

 

Missing Function Level Access Control

 

Cross-Site-Request-Forgery (CSRF)

 

Using Known Vulnerable Components

 

Unvalidated Redirects and Forwards

Firmware updates and cryptographic signatures

 

Identity management

 

Embedded software frameworks

 

Debug interface

 

Network protocols

 

Authentication procedure

 

Buffer and stack overflow

 

Sending of arbitrary data on in-vehicle bus systems (CAN, LIN, Flexray etc.)

 

Unlocking a vehicle

 

Remote-code-execution

 

Compromise of the update mechanism, e. g. flashing an ECU with unauthorized firmware

 

Infringement of GDPR-specifications: collection, usage, storage and revealing of sensitive data