qbilon GmbH is committed to the security of our software and our customers. We value the work of security researchers and users who report vulnerabilities to us, and we commit to fair and transparent cooperation.
This policy applies to
Note: Our website and the reporting contact are located on a separate domain (qbilon.io).
Please report vulnerabilities exclusively to security@qbilon.io
Please do NOT report vulnerabilities through public channels such as social media, GitHub issues or forums.
These timelines are target values and not legally guaranteed deadlines. Independently of this, we additionally report actively exploited vulnerabilities with significant risk to the competent authorities (BSI/ENISA under the EU Cyber Resilience Act) within the legally prescribed deadlines.
We ask for a reasonable period of usually 90 days after the initial report before details are made public. A joint publication is possible by arrangement.
Reports made in good faith, within the scope of this policy, and without access to systems or data beyond what is necessary for reproduction are not considered abusive conduct by us. In such cases, qbilon GmbH will not initiate its own criminal or civil proceedings against the reporter.
This commitment binds qbilon GmbH as the party entitled to file a complaint. It cannot fully exclude prosecution by third parties or ex officio (e.g. under Section 202a of the German Criminal Code). However, we actively work to ensure that compliant reporters suffer no disadvantages, and we support reporters in the event of inquiries by authorities.
We currently do not offer a bug bounty program with financial compensation. With your consent, we will gladly name you in our Hall of Fame or in the release notes of the respective fix.
Personal data submitted as part of a report (e.g. name, email address) is processed exclusively to handle your report. For details, please see our privacy policy.
This policy is governed by German law. Reports may be submitted in German or English.