HighQSoft GmbH Vulnerability Disclosure Policy (VDP)

HighQSoft GmbH welcomes security researchers and the public to responsibly report potential security vulnerabilities.

This policy explains how to report vulnerabilities, what testing is in scope, and how HighQSoft GmbH will handle reports.

Contact

Contact

Please report vulnerabilities to:

If your report contains sensitive details, encrypt it using our public key:

  • PGP key download: https://www.highqsoft.com/wp-content/uploads/HighQSoft-PSIRT-public.key
  • Primary key fingerprint: BD8D BBD4 B1F8 14A7 A21D 6A4F 9F99 B119 CA66 6DC3

Scope

Scope

The following targets are in scope when they are owned or operated by HighQSoft GmbH:

  • Public websites
  • Public APIs
  • Desktop and client software

Out of Scope

Out of Scope

The following activities are out of scope:

  • Social engineering, phishing, or pretexting
  • Physical security testing
  • Any systems, services, or infrastructure not owned by HighQSoft GmbH

Rules of Engagement

Rules of Engagement

When conducting security testing, you must:

  • Act in good faith and avoid privacy violations, data destruction, and service disruption
  • Use only techniques necessary to confirm the vulnerability
  • Stop testing immediately after confirming a finding
  • Not access, modify, or retain data beyond what is strictly required for proof of concept
  • Not publicly disclose vulnerability details unless HighQSoft GmbH gives prior written approval

Safe Harbor

Safe Harbor

HighQSoft GmbH will not pursue legal action against researchers who:

  • Follow this policy in good faith
  • Stay within scope and the rules of engagement
  • Promptly report vulnerabilities and provide reasonable cooperation during validation and remediation

If your activities accidentally affect systems or data, notify us immediately.

What to Include in a Report

What to Include in a Report

Please include:

  • A clear description of the issue and affected asset
  • Steps to reproduce the issue
  • Proof of concept (screenshots, logs, request/response samples, or exploit details)
  • Security impact and potential business risk
  • Suggested remediation, if available

Response and Handling Timelines

Response and Handling Timelines

HighQSoft GmbH aims to:

  • Acknowledge receipt within 5 business days
  • Complete initial triage within 15 business days
  • Provide status updates monthly for accepted reports until closure

Complex issues may require additional time. We will communicate timeline changes when possible.

Disclosure and Communications

Disclosure and Communications

  • Reports are handled as coordinated disclosures.
  • Public disclosure by researchers requires prior written approval from HighQSoft GmbH.
  • HighQSoft GmbH may publish advisories when appropriate.

Rewards and Acknowledgment

Rewards and Acknowledgment

HighQSoft GmbH does not currently operate a paid bug bounty program.

At our discretion, we may acknowledge valid reports in a public acknowledgment list, subject to reporter consent.

Privacy and Data Handling

Privacy and Data Handling

  • Do not include unnecessary personal data in reports.
  • HighQSoft GmbH will process submitted information only for security triage, remediation, and related communications.

Policy Changes

Policy Changes

HighQSoft GmbH may update this policy at any time.

Effective date: 2026-07-01

Owner: HighQSoft PSIRT

Anonymous web formular

Anonymous web formular

You can also share the information you have with us anonymously by using the following web formular to send an anonymous report. Please note that we will not collect any personal data from you when using this approach. Please also note that we will not be able to send any follow-up questions regarding a report.

Provide the name of the software you want to report a security issue with.
Provide the version of the software that you encountered a security issue with. The version is typically formatted as '26.1.4' or '2.7.10'
Additional input
Select any options that are applicable to the security incident you wish to report.
Provide details on the exact nature of the security issue. If there are steps to re-create the issue, please provide them here.

HighQSoft GmbH

Black-und-Decker-Straße 17b
D-65510 Idstein