HighQSoft GmbH welcomes security researchers, customers and the public to responsibly report potential security vulnerabilities in our products and services.
This policy explains what is in scope, how to report a vulnerability, what you can expect from us, and how disclosure is coordinated. It is the public counterpart to our internal vulnerability and security incident handling procedure.
Policy version 2.0. Effective date: 2026-08-05. Owner: HighQSoft PSIRT. Reviewed at least annually.
Please report vulnerabilities through one of the following channels.
Anonymous reports are accepted and are handled the same way as attributed ones. Note that we cannot ask follow up questions on an anonymous report, which may limit what we can validate.
If your report contains sensitive details, encrypt it with our public key.
BD8D BBD4 B1F8 14A7 A21D 6A4F 9F99 B119 CA66 6DC3Preferred languages: English, German.
This policy covers HighQSoft GmbH products, together with the third party and open source components bundled with them, and the assets we operate ourselves.
Products:
If a HighQSoft product is not named above, report the finding anyway. We would rather receive a report about something we forgot to list than not receive it.
Which versions are in scope. A version is in scope for as long as it is inside its security support period.
Every version of every product receives security updates free of charge for at least five years from that version's release date. That period is independent of any maintenance contract: whether a maintenance agreement is active does not change whether a version is in scope here, and it does not change our obligation to fix a confirmed vulnerability. A version therefore stays in scope until its published End of Security Support date, and a product that is no longer sold is still in scope for every version that has not reached that date.
If you are unsure whether a version is still supported, or if the End of Security Support date for your version is not published, report the finding and we will tell you. Versions that have passed their End of Security Support date are out of scope for this policy, but we will still tell you what we intend to do.
The following are out of scope:
When conducting security testing, you must:
If you make a good faith effort to comply with this policy during your security research, HighQSoft GmbH considers your research authorized, will work with you to understand and resolve the issue quickly, and will not initiate or recommend legal action in relation to that research. This includes not filing a criminal complaint under sections 202a to 202c of the German Criminal Code (StGB) and not pursuing civil claims arising from research conducted within this policy.
If a third party initiates action against you for research you carried out in compliance with this policy, we will make your compliance known.
If your activities accidentally affect systems or data beyond the scope of this policy, notify us immediately; a prompt, honest report is treated as good faith.
Please include:
Here is what you can expect from us after you submit a report.
| Step | Our commitment |
|---|---|
| Acknowledge receipt of your report | within 5 business days |
| Complete initial triage and tell you our assessment | within 10 business days |
| Status updates on an accepted report | monthly until closure |
Target remediation windows once a report is confirmed, by severity, scored with the CVSS base score:
| Severity | CVSS base | Target |
|---|---|---|
| Critical | 9.0 to 10.0 | Prioritized above other development work. Interim mitigation or workaround as soon as available; fix targeted within 30 calendar days. |
| High | 7.0 to 8.9 | Fix in the next scheduled release, targeted within 90 calendar days. |
| Medium | 4.0 to 6.9 | Scheduled into maintenance, targeted within 180 calendar days; may be batched with other fixes. |
| Low | 0.1 to 3.9 | Tracked and addressed in routine maintenance. |
These targets apply to every reporter, with or without a commercial relationship, and are escalated when there is credible evidence of exploitation in the wild. Customers under a Software Maintenance agreement may receive faster fixes through their SLA.
Complex issues may take longer; where a target is at risk we will tell you and explain why.
HighQSoft GmbH practises coordinated vulnerability disclosure.
We do not operate a paid bug bounty program.
Do not include unnecessary personal data in a report. HighQSoft GmbH processes the information you submit only for security triage, remediation and the related communication with you.
HighQSoft GmbH may update this policy. The current version and effective date are shown at the top of this page.
You can also share what you have with us anonymously using the web form below. We will not collect any personal data from you when you use it, and we will not be able to send follow up questions about an anonymous report.
HighQSoft GmbH
Black-und-Decker-Straße 17b
D-65510 Idstein
You are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from hCaptcha to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information