X-Software GmbH is committed to the security of our products and services. We welcome reports from security researchers, customers, and partners who discover potential security vulnerabilities. This Coordinated Vulnerability Disclosure (CVD) Policy describes how to report vulnerabilities and what you can expect from us in return.
This policy is maintained in compliance with the EU Cyber Resilience Act (Regulation (EU) 2024/2847), Article 13, and ISO/IEC 29147.
This policy applies to the following X-Software GmbH products and services:
Report security vulnerabilities to our security team via:
Please include:
X-Software GmbH commits to the following response timeline:
| Milestone | Target |
|---|---|
| Acknowledgment | Within 48 hours |
| Initial severity assessment | Within 5 business days |
| Status updates | At least every 30 days |
| Critical patch | Within 7 days |
| High patch | Within 30 days |
| Medium patch | Within 90 days |
X-Software GmbH requests a coordinated disclosure period of 90 days from the date of your report. We ask that you refrain from publishing vulnerability details until a patch or advisory is available, or until the 90-day period has elapsed.
If a vulnerability is actively being exploited, we may accelerate the timeline and issue an advisory with or without a complete fix. We will always notify you before public disclosure.
X-Software GmbH will not pursue legal action against researchers who:
Safe harbour does not extend to the following prohibited activities:
X-Software GmbH does not currently offer monetary rewards for vulnerability reports.
With your permission, we will acknowledge your contribution in the security advisory for the vulnerability.
Where a reported vulnerability is actively exploited in the wild or constitutes a severe security incident, X-Software GmbH will notify ENISA within 24 hours (early warning) and 72 hours (full notification) under Article 14 of the EU Cyber Resilience Act.
Last updated: 2026-08-04