← Back to home
Coordinated Vulnerability Disclosure Policy
Our Commitment to Security
iQLASE takes the security of our products seriously. We recognise that independent security researchers play an important role in identifying vulnerabilities before they can be exploited.
This Responsible Disclosure Policy sets out how to report security vulnerabilities to us, and what you can expect from us in return.
What We Ask of Researchers
When researching and reporting vulnerabilities, please:
- Act in good faith – do not intentionally harm iQLASE, our users, or our services
- Minimise impact – only access the data necessary to demonstrate the vulnerability
- Report promptly – notify us as soon as you discover a potential vulnerability
- Coordinate disclosure – give us reasonable time to respond before publishing
- Keep it confidential – do not share details with others until we have addressed the issue
- Follow the law – research within the bounds of applicable law
How to Report
Email: security@iqlase.de
Please include:
- Which product or service is affected
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Any relevant screenshots or proof-of-concept code
We do not accept vulnerability reports via support tickets, social media, or public forums.
What to Expect from Us
When you submit a vulnerability report, iQLASE will:
- Acknowledge your report within 72 hours
- Keep you informed of our investigation progress
- Work with you to understand and validate the issue
- Notify you when we have released a fix
- Credit you publicly for your discovery (if you wish)
- Not pursue legal action against you for good-faith research under this policy
Disclosure Timeline
iQLASE follows a 90-day disclosure window from initial report. This means:
- We aim to release a patch or advisory within 90 days of your report
- We will discuss the timeline with you if we need more time
- We will provide advance notice before we publish our advisory
- We will coordinate with you on the content of any public disclosure
If a vulnerability is being actively exploited in the wild, we will prioritise faster remediation and disclosure.
Safe Harbour
If you discover and report a vulnerability in good faith and in accordance with this policy, iQLASE will not:
- Pursue legal or civil action against you
- Report you to law enforcement
- Terminate or restrict your access to our products solely because of your research
This safe harbour applies provided you did not intentionally access data beyond your own, did not disrupt our services, and reported to us before any public disclosure.