Report suspected security vulnerabilities in VARIOS AI to security@varios-ai.com. We take every report seriously and treat it confidentially.
What you can report
What your report should contain
- Affected version and release branch, found under Settings > System information
- Description of the vulnerability and its possible impact
- Steps to reproduce, with a proof of concept if available
- Your contact details for follow-up questions
We communicate in German or English.
How we handle your report
Acknowledgement
We confirm receipt within three working days.
Assessment
We review the report, assess its severity and inform you of the result.
Fix
We fix confirmed vulnerabilities without undue delay and provide an update for all supported versions.
Publication
Once the update is available, we publish a security notice in the changelog. On request, we credit you as the reporter.
Coordinated disclosure
Please do not publish details of a vulnerability until an update is available, and at the latest 90 days after your report. If we need longer, we agree on the date with you.
Anyone who searches for vulnerabilities in good faith and within this policy need not expect legal action from us. Access only the data required for the proof and delete it afterwards.
For vulnerabilities that are being actively exploited, we inform our customers’ administrators directly. We name the affected versions and recommend measures until the update is installed.
Check regularly under Settings > System information whether an update is available.