Guidelines for the Coordinated Reporting of Security Vulnerabilities (CVD)
The security of our products and systems is a high priority for Variolytics GmbH. We welcome reports from customers, security researchers and other third parties regarding potential security vulnerabilities in our products.
Scope
This policy applies to products with digital elements provided by Variolytics GmbH and the associated software, firmware and product-related digital components.
In Scope
Out of scope
Unless expressly agreed otherwise, the following systems or activities are outside the scope of this policy:
If you are unsure whether a product, system or testing method is in scope, please contact us before carrying out further testing.
Reporting a Vulnerability
If you discover a potential vulnerability, please submit your report using the following contact details:
|
Security Email |
security@variolytics.com |
|
Recommended Subject Line |
Security Vulnerability Report – [Product Name] |
To enable us to analyze your report efficiently, please include as much of the following information as possible:
Please do not submit personal data, confidential information or other protected information that is not necessary for analyzing the vulnerability.
How We Handle Your Report
We aim to acknowledge receipt of your report within 3 business days, assess the vulnerability, develop appropriate remediation measures, and coordinate the publication of information with the reporting party where possible.
Coordinated Disclosure
Please do not publish or share detailed information about an unresolved vulnerability without prior coordination with us. Variolytics will seek to address confirmed vulnerabilities without undue delay.
Treatment of Security Researchers
Where security research is conducted in good faith, within the scope of this policy and without malicious intent, Variolytics does not intend – to the extent legally permissible – to initiate legal action solely as a result of such security research. This statement does not constitute a general authorization to violate applicable law, contractual obligations or third-party rights.
Regulatory Reporting Obligations
Certain vulnerabilities or security incidents may be subject to statutory reporting obligations. Variolytics reserves the right to share information with competent authorities or CSIRTs to the extent required by law. This applies in particular to reporting obligations under Regulation (EU) 2024/2847 (Cyber Resilience Act).
Compensation
Variolytics does not currently operate a bug bounty programme.
Contact
You can read the complete guideline (Version 1.0, approved) here.