Coordinated Vulnerability
Disclosure Policy
Coordinated Vulnerability
Disclosure Policy
Manufacturer: Qundis GmbH
Version: 1.0
Created: 27 August 2026
Last modified: 27 August 2026
Next review: 27 August 2027
1. Overview and Scope
Qundis GmbH welcomes responsible reports of suspected security vulnerabilities affecting our products and infrastructure. Researchers and other parties who identify a potential vulnerability can submit a report to our security team by email. Please provide sufficient information to enable us to understand, reproduce, and assess the reported issue.
This CVD Policy applies to vulnerabilities affecting Qundis GmbH products and infrastructure.
Qundis GmbH reviews this policy at least once per year and keeps it up to date.
2. Vulnerability Reporting
Vulnerabilities can be reported through:
Qundis GmbH accepts vulnerability reports by email only.
Qundis GmbH treats all incoming vulnerability reports to the best extent possible. No incoming report is closed by a single analyst.
A valid vulnerability is a vulnerability affecting a Qundis GmbH product or Qundis GmbH infrastructure.
3. Confidentiality and Reporting Entity Protection
Qundis GmbH treats each vulnerability report confidentially to the extent permitted by law. Information required for public disclosure of a vulnerability is excluded from this confidentiality obligation.
Personal data of the reporting entity is not disclosed to third parties without the explicit consent of the reporting entity.
Qundis GmbH will not pursue criminal charges against a reporting entity that complies with this policy and its principles. This does not apply where recognizable criminal intentions have been or are being pursued.
Qundis GmbH remains available as a contact for a trustful exchange throughout the entire CVD process.
Reporting vulnerabilities is appreciated and helps Qundis GmbH improve the security of its products and services. However, submission of a vulnerability report does not create any entitlement to a monetary reward, bounty, or other financial compensation.
4. Content of Vulnerability Report
To help assess and investigate a reported vulnerability efficiently, as much relevant information as possible should be provided. A complete report should include, where applicable:
5. Out of Scope Elements
The following issues are generally considered outside the scope of this Coordinated Vulnerability Disclosure process: