← Back to home

Coordinated Vulnerability Disclosure Policy

Our Commitment to Security

iQLASE takes the security of our products seriously. We recognise that independent security researchers play an important role in identifying vulnerabilities before they can be exploited.

This Responsible Disclosure Policy sets out how to report security vulnerabilities to us, and what you can expect from us in return.

What We Ask of Researchers

When researching and reporting vulnerabilities, please:

  • Act in good faith – do not intentionally harm iQLASE, our users, or our services
  • Minimise impact – only access the data necessary to demonstrate the vulnerability
  • Report promptly – notify us as soon as you discover a potential vulnerability
  • Coordinate disclosure – give us reasonable time to respond before publishing
  • Keep it confidential – do not share details with others until we have addressed the issue
  • Follow the law – research within the bounds of applicable law

How to Report

Email: security@iqlase.de

Please include:

  • Which product or service is affected
  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any relevant screenshots or proof-of-concept code

We do not accept vulnerability reports via support tickets, social media, or public forums.

What to Expect from Us

When you submit a vulnerability report, iQLASE will:

  • Acknowledge your report within 72 hours
  • Keep you informed of our investigation progress
  • Work with you to understand and validate the issue
  • Notify you when we have released a fix
  • Credit you publicly for your discovery (if you wish)
  • Not pursue legal action against you for good-faith research under this policy

Disclosure Timeline

iQLASE follows a 90-day disclosure window from initial report. This means:

  • We aim to release a patch or advisory within 90 days of your report
  • We will discuss the timeline with you if we need more time
  • We will provide advance notice before we publish our advisory
  • We will coordinate with you on the content of any public disclosure

If a vulnerability is being actively exploited in the wild, we will prioritise faster remediation and disclosure.

Safe Harbour

If you discover and report a vulnerability in good faith and in accordance with this policy, iQLASE will not:

  • Pursue legal or civil action against you
  • Report you to law enforcement
  • Terminate or restrict your access to our products solely because of your research

This safe harbour applies provided you did not intentionally access data beyond your own, did not disrupt our services, and reported to us before any public disclosure.