Skip to main content
Report suspected security vulnerabilities in VARIOS AI to security@varios-ai.com. We take every report seriously and treat it confidentially.

What you can report

What your report should contain

  • Affected version and release branch, found under Settings > System information
  • Description of the vulnerability and its possible impact
  • Steps to reproduce, with a proof of concept if available
  • Your contact details for follow-up questions
We communicate in German or English.

How we handle your report

1

Acknowledgement

We confirm receipt within three working days.
2

Assessment

We review the report, assess its severity and inform you of the result.
3

Fix

We fix confirmed vulnerabilities without undue delay and provide an update for all supported versions.
4

Publication

Once the update is available, we publish a security notice in the changelog. On request, we credit you as the reporter.

Coordinated disclosure

Please do not publish details of a vulnerability until an update is available, and at the latest 90 days after your report. If we need longer, we agree on the date with you. Anyone who searches for vulnerabilities in good faith and within this policy need not expect legal action from us. Access only the data required for the proof and delete it afterwards.

Informing our customers

For vulnerabilities that are being actively exploited, we inform our customers’ administrators directly. We name the affected versions and recommend measures until the update is installed.
Check regularly under Settings > System information whether an update is available.