QbilonQbilon

Vulnerability Disclosure Policy

Commitment

qbilon GmbH is committed to the security of our software and our customers. We value the work of security researchers and users who report vulnerabilities to us, and we commit to fair and transparent cooperation.

Scope

This policy applies to

  • our SaaS products Qbilon CMDB and Qbilon Platform, provided under *.qbilon.net, and
  • our on-premises products Qbilon CMDB, Qbilon Platform and Qbilon Suite (the current version as well as the two preceding major versions).

Note: Our website and the reporting contact are located on a separate domain (qbilon.io).

Out of scope

  • Denial-of-service attacks,
  • Social engineering, phishing against employees,
  • Physical access to premises, and
  • Access to or manipulation of third-party customer data.

How to report

Please report vulnerabilities exclusively to security@qbilon.io

Please do NOT report vulnerabilities through public channels such as social media, GitHub issues or forums.

Required information

  • Affected product and version,
  • Description of the vulnerability and potential impact, and
  • Steps to reproduce (proof of concept without data access, without exploitation against production systems or customer data).

Our process

  • Acknowledgment of receipt within 3 business days
  • Initial assessment/prioritization within 10 business days
  • Status update at least every 30 days until remediation
  • We will inform you as soon as a patch is available.

These timelines are target values and not legally guaranteed deadlines. Independently of this, we additionally report actively exploited vulnerabilities with significant risk to the competent authorities (BSI/ENISA under the EU Cyber Resilience Act) within the legally prescribed deadlines.

Coordinated disclosure

We ask for a reasonable period of usually 90 days after the initial report before details are made public. A joint publication is possible by arrangement.

Responsible conduct and its limits

Reports made in good faith, within the scope of this policy, and without access to systems or data beyond what is necessary for reproduction are not considered abusive conduct by us. In such cases, qbilon GmbH will not initiate its own criminal or civil proceedings against the reporter.

This commitment binds qbilon GmbH as the party entitled to file a complaint. It cannot fully exclude prosecution by third parties or ex officio (e.g. under Section 202a of the German Criminal Code). However, we actively work to ensure that compliant reporters suffer no disadvantages, and we support reporters in the event of inquiries by authorities.

Compensation

We currently do not offer a bug bounty program with financial compensation. With your consent, we will gladly name you in our Hall of Fame or in the release notes of the respective fix.

Data protection

Personal data submitted as part of a report (e.g. name, email address) is processed exclusively to handle your report. For details, please see our privacy policy.

Applicable law and language

This policy is governed by German law. Reports may be submitted in German or English.

Contact