HighQSoft GmbH Vulnerability Disclosure Policy (VDP)

HighQSoft GmbH welcomes security researchers, customers and the public to responsibly report potential security vulnerabilities in our products and services.

This policy explains what is in scope, how to report a vulnerability, what you can expect from us, and how disclosure is coordinated. It is the public counterpart to our internal vulnerability and security incident handling procedure.

Policy version 2.0. Effective date: 2026-08-05. Owner: HighQSoft PSIRT. Reviewed at least annually.

Contact

Contact

Please report vulnerabilities through one of the following channels.

Anonymous reports are accepted and are handled the same way as attributed ones. Note that we cannot ask follow up questions on an anonymous report, which may limit what we can validate.

If your report contains sensitive details, encrypt it with our public key.

Preferred languages: English, German.

Scope

Scope

This policy covers HighQSoft GmbH products, together with the third party and open source components bundled with them, and the assets we operate ourselves.

Products:

  • AReS Libertas ODS Server, the AReS ODS6 Server and the AReS Gateway
  • ASAMCommander (Lite, Professional and Enterprise) and its modules
  • Merlin Analysis Server and Analysis Workflow Automation
  • HQL, the HQL Web Service, the HQL Gateway and the HQL toolboxes (matHQL, pyHQL)
  • Avalon ODS Server, for versions still inside their security support period
  • The ODS5 to ODS6 migration gateway and the data integration services we deliver as products

If a HighQSoft product is not named above, report the finding anyway. We would rather receive a report about something we forgot to list than not receive it.

Which versions are in scope. A version is in scope for as long as it is inside its security support period.

Every version of every product receives security updates free of charge for at least five years from that version's release date. That period is independent of any maintenance contract: whether a maintenance agreement is active does not change whether a version is in scope here, and it does not change our obligation to fix a confirmed vulnerability. A version therefore stays in scope until its published End of Security Support date, and a product that is no longer sold is still in scope for every version that has not reached that date.

If you are unsure whether a version is still supported, or if the End of Security Support date for your version is not published, report the finding and we will tell you. Versions that have passed their End of Security Support date are out of scope for this policy, but we will still tell you what we intend to do.

Out of Scope

Out of Scope

The following are out of scope:

  • Social engineering, phishing and pretexting
  • Physical security testing
  • Denial of service and load or stress testing
  • Any system, service or infrastructure not owned or operated by HighQSoft GmbH, including customer installations and third party services
  • Reports that consist only of automated scanner output with no demonstrated impact

Rules of Engagement

Rules of Engagement

When conducting security testing, you must:

  • Act in good faith and avoid privacy violations, data destruction and service disruption
  • Use only the techniques necessary to confirm the vulnerability
  • Stop testing immediately after confirming a finding
  • Not access, modify or retain data beyond what is strictly required for a proof of concept
  • Coordinate publication with us as described under Disclosure below

Safe Harbor

Safe Harbor

If you make a good faith effort to comply with this policy during your security research, HighQSoft GmbH considers your research authorized, will work with you to understand and resolve the issue quickly, and will not initiate or recommend legal action in relation to that research. This includes not filing a criminal complaint under sections 202a to 202c of the German Criminal Code (StGB) and not pursuing civil claims arising from research conducted within this policy.

If a third party initiates action against you for research you carried out in compliance with this policy, we will make your compliance known.

If your activities accidentally affect systems or data beyond the scope of this policy, notify us immediately; a prompt, honest report is treated as good faith.

What to Include in a Report

What to Include in a Report

Please include:

  • A clear description of the issue and the affected product, version and asset
  • Steps to reproduce
  • Proof of concept (screenshots, logs, request and response samples, or exploit details)
  • Security impact and potential business risk
  • Suggested remediation, if you have one

What to Expect

What to Expect From Us

Here is what you can expect from us after you submit a report.

Step Our commitment
Acknowledge receipt of your report within 5 business days
Complete initial triage and tell you our assessment within 10 business days
Status updates on an accepted report monthly until closure

Target remediation windows once a report is confirmed, by severity, scored with the CVSS base score:

Severity CVSS base Target
Critical 9.0 to 10.0 Prioritized above other development work. Interim mitigation or workaround as soon as available; fix targeted within 30 calendar days.
High 7.0 to 8.9 Fix in the next scheduled release, targeted within 90 calendar days.
Medium 4.0 to 6.9 Scheduled into maintenance, targeted within 180 calendar days; may be batched with other fixes.
Low 0.1 to 3.9 Tracked and addressed in routine maintenance.

These targets apply to every reporter, with or without a commercial relationship, and are escalated when there is credible evidence of exploitation in the wild. Customers under a Software Maintenance agreement may receive faster fixes through their SLA.

Complex issues may take longer; where a target is at risk we will tell you and explain why.

Disclosure

Disclosure

HighQSoft GmbH practises coordinated vulnerability disclosure.

  • We work with you to validate and fix the issue, then publish a security advisory when a fix or mitigation is available. Where a vulnerability affects a released product, we request a CVE identifier.
  • The default coordination window is 90 calendar days from our acknowledgement of your report. We ask you not to publish details before the coordinated date or before the window expires, whichever comes first.
  • If we need longer, for example because a fix requires a coordinated release with a third party, we will ask you and explain why. We will not withhold agreement unreasonably.
  • If we fail to respond or to remediate within the window, you are free to publish. We would rather you disclose than that the issue stay unfixed.
  • With your consent we credit you in the advisory. You may also ask to remain anonymous.

We do not operate a paid bug bounty program.

Privacy and Data Handling

Privacy and Data Handling

Do not include unnecessary personal data in a report. HighQSoft GmbH processes the information you submit only for security triage, remediation and the related communication with you.

Policy Changes

Policy Changes

HighQSoft GmbH may update this policy. The current version and effective date are shown at the top of this page.

Anonymous web form

Anonymous web form

You can also share what you have with us anonymously using the web form below. We will not collect any personal data from you when you use it, and we will not be able to send follow up questions about an anonymous report.

Provide the name of the software you want to report a security issue with.
Provide the version of the software that you encountered a security issue with. The version is typically formatted as '26.1.4' or '2.7.10'
Additional input
Select any options that are applicable to the security incident you wish to report.
Provide details on the exact nature of the security issue. If there are steps to re-create the issue, please provide them here.

HighQSoft GmbH

Black-und-Decker-Straße 17b
D-65510 Idstein