Coordinated Vulnerability Disclosure Policy

1. Introduction

X-Software GmbH is committed to the security of our products and services. We welcome reports from security researchers, customers, and partners who discover potential security vulnerabilities. This Coordinated Vulnerability Disclosure (CVD) Policy describes how to report vulnerabilities and what you can expect from us in return.

This policy is maintained in compliance with the EU Cyber Resilience Act (Regulation (EU) 2024/2847), Article 13, and ISO/IEC 29147.

2. Scope

This policy applies to the following X-Software GmbH products and services:

  • MXL Recorder
  • MXL Player

3. How to Report

Report security vulnerabilities to our security team via:

Please include:

  • Product name and version
  • Description of the vulnerability and its potential impact
  • Step-by-step reproduction instructions
  • Proof of concept (screenshots, code, or video)

4. Our Commitments

X-Software GmbH commits to the following response timeline:

MilestoneTarget
AcknowledgmentWithin 48 hours
Initial severity assessmentWithin 5 business days
Status updatesAt least every 30 days
Critical patchWithin 7 days
High patchWithin 30 days
Medium patchWithin 90 days

5. Coordinated Disclosure

X-Software GmbH requests a coordinated disclosure period of 90 days from the date of your report. We ask that you refrain from publishing vulnerability details until a patch or advisory is available, or until the 90-day period has elapsed.

If a vulnerability is actively being exploited, we may accelerate the timeline and issue an advisory with or without a complete fix. We will always notify you before public disclosure.

6. Safe Harbour

X-Software GmbH will not pursue legal action against researchers who:

  • Discover and report vulnerabilities in good faith under this policy
  • Limit testing to systems they own or have explicit permission to test
  • Avoid intentional service disruption or data access beyond proof of concept
  • Notify us before any public disclosure
  • Comply with applicable law

Safe harbour does not extend to the following prohibited activities:

  • Introducing malware, backdoors, or other malicious code
  • Copying, editing, or deleting data beyond minimal proof of access
  • Making changes to the system or its configuration
  • Repeatedly accessing the system or sharing obtained access with others
  • Brute-force attacks against systems or accounts
  • Denial-of-service attacks
  • Social engineering against our employees

7. Recognition

X-Software GmbH does not currently offer monetary rewards for vulnerability reports.

With your permission, we will acknowledge your contribution in the security advisory for the vulnerability.

8. CRA Article 14 Obligations

Where a reported vulnerability is actively exploited in the wild or constitutes a severe security incident, X-Software GmbH will notify ENISA within 24 hours (early warning) and 72 hours (full notification) under Article 14 of the EU Cyber Resilience Act.


Last updated: 2026-08-04