Procedure for the
Coordinated Disclosure
of Vulnerabilities (CVD Policy)
Procedure for the
Coordinated Disclosure
of Vulnerabilities (CVD Policy)
Manufacturer: Qundis GmbH
Version: 1.0
Created: 3 September 2026
Last modified: 3 September 2026
Next review: 3 September 2027
1. Purpose and scope
We, QUNDIS GmbH, welcome responsible reports of suspected vulnerabilities affecting our products with digital elements. Security researchers and other individuals who identify a potential vulnerability may report it to our security team by email. Please provide sufficient information to enable us to understand, reproduce, assess and, where appropriate, resolve the reported issue.
This procedure applies to vulnerabilities affecting products with digital elements from QUNDIS GmbH.
We review this procedure at least once a year and keep it up to date.
2. How to report a vulnerability.
Vulnerabilities can be reported to us at the following email address:
We accept vulnerability reports by email only.
We handle all incoming vulnerability reports to the best of our knowledge and belief. No report is closed solely on the basis of one person's assessment.
A vulnerability is considered valid if it concerns a product with digital elements from QUNDIS GmbH.
3. Confidentiality and protection of reporters
We treat every vulnerability report as confidential to the extent permitted by law. This does not apply to information required for the coordinated disclosure of a vulnerability.
Personal data relating to a reporter will not be disclosed to third parties without the reporter's explicit consent, unless this is required in connection with an official investigation.
We will not initiate criminal proceedings against reporters provided that they comply with the requirements and principles of this procedure. This does not apply where criminal intent was or is evident.
We remain available for a confidential dialogue throughout the CVD process.
We expressly welcome reports of vulnerabilities, as they help us improve the security of our products. However, submitting a vulnerability report does not create any entitlement to a financial reward, bug bounty or other remuneration.
4. Information to include in your report.
To help us assess and investigate a reported vulnerability efficiently, please provide as much relevant information as possible. Where applicable, a complete report should include the following:
5. Excluded matters
The following matters generally fall outside this coordinated vulnerability disclosure process: