> ## Documentation Index
> Fetch the complete documentation index at: https://docs.varios-ai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Report Security Vulnerabilities

> How to report a suspected security vulnerability to us and how we handle it

Report suspected security vulnerabilities in VARIOS AI to **[security@varios-ai.com](mailto:security@varios-ai.com)**. We take every report seriously and treat it confidentially.

## What you can report

| In scope | Out of scope |
| - | - |
| VARIOS AI in all supported versions, self-hosted and hosted by us | Attacks that disrupt availability (denial of service) |
| VARIOS AI Office add-ins | Social engineering and phishing against employees |
| Container images delivered by VARIOS AI | Third-party services such as AI providers or identity providers |
| | Vulnerabilities in versions that are no longer supported |

## What your report should contain

* Affected version and release branch, found under **Settings** > **System information**
* Description of the vulnerability and its possible impact
* Steps to reproduce, with a proof of concept if available
* Your contact details for follow-up questions

We communicate in German or English.

## How we handle your report

<Steps>
  <Step title="Acknowledgement">
    We confirm receipt within three working days.
  </Step>

  <Step title="Assessment">
    We review the report, assess its severity and inform you of the result.
  </Step>

  <Step title="Fix">
    We fix confirmed vulnerabilities without undue delay and provide an update for all supported versions.
  </Step>

  <Step title="Publication">
    Once the update is available, we publish a security notice in the [changelog](../changelog/changelog). On request, we credit you as the reporter.
  </Step>
</Steps>

## Coordinated disclosure

Please do not publish details of a vulnerability until an update is available, and at the latest 90 days after your report. If we need longer, we agree on the date with you.

Anyone who searches for vulnerabilities in good faith and within this policy need not expect legal action from us. Access only the data required for the proof and delete it afterwards.

## Informing our customers

For vulnerabilities that are being actively exploited, we inform our customers' administrators directly. We name the affected versions and recommend measures until the update is installed.

<Tip>
  Check regularly under **Settings** > **System information** whether an update is available.
</Tip>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.