INFORM Coordinated Vulnerability Disclosure (CVD) Policy

Report a vulnerability

INFORM welcomes reports of security vulnerabilities in products with digital elements and related product-specific services for which INFORM is responsible. This policy describes how vulnerabilities can be reported responsibly, what minimum information a report should contain, and how INFORM processes incoming reports and — to the extent appropriate — coordinates their disclosure.

 

Scope

This policy applies only to products with digital elements developed, distributed, or maintained by INFORM, as well as to associated cloud services for which INFORM is responsible, to the extent that their absence would impair or prevent product functionality.

 

Principles

Individuals acting within the limits of this CVD Policy and in good faith need not fear any legal consequences because of their vulnerability report. However, INFORM reserves the right to take legal action in the event of any violations of this policy.

 

How to report a vulnerability

Please report vulnerabilities via the security contact channels published by INFORM. The most current contact information and references to this policy are also published via the  security.txt file in accordance with RFC 9116.

Primary security contact

Preferred languages: German, English.

security-reports@inform-software.com

 

Web form

Communication via the web form is encrypted.

Go to form

Anonymous reports are generally possible. Please note that the lack of opportunities to address follow-up questions may make validation, prioritization, and feedback more difficult.

 

Key elements of a good report

  1. Affected product, component, or service — including version information, if applicable
  2. Description of the vulnerability and its potential security impact
  3. Steps to reproduce the exploit, as well as any technical prerequisites
  4. Indication of whether active exploitation is merely suspected or has already been observed
  5. Contact information for follow-up questions (optional, but recommended)

 

Expectations towards reporting individuals

  • Acting solely for the purpose of improving security — without any fraudulent, harmful, or extortionate intentions.
  • No unnecessary access to, modification of, or deletion of data.
  • Refrain from any actions that impair availability, including, but not limited to, load, stress, or denial-of-service tests, or procedures with similar effects.
  • Refrain from social engineering.
  • Do not publish or share information with third parties without prior consultation with INFORM.

INFORM generally does not require the signing of a separate non-disclosure agreement (NDA) for the acceptance of a vulnerability report.

 

Processing by INFORM

  • Acknowledgment of receipt: provided a communication channel is available or has been specified, generally within 5 business days.
  • Initial professional feedback: generally, within 10 business days following acknowledgment of receipt (this may also include validation and/or follow-up questions).
  • Further status updates: an update will be provided as soon as additional verified information becomes available. The timing of this update depends on the specific nature of the incident, the severity assessment, and possible external factors.
  • No entitlement to compensation: this policy is not a bug bounty program and does not constitute a basis for a claim for payment.
  • If, following an investigation by INFORM, it is determined that the issue is a vulnerability subject to mandatory reporting or a severe security incident according to the provisions of the Cyber Resilience Act, INFORM will fulfill its regulatory reporting obligations within the statutory timeframe.
     

Confidentiality, data protection and coordinated disclosure

INFORM in principle treats incoming vulnerability reports as confidential.

Where personal data is provided by the reporting individual, it will be processed exclusively for the purpose of further handling the vulnerability report and in compliance with the GDPR.

INFORM follows the principle of coordinated disclosure and strives to disclose validated and verified vulnerabilities in an appropriate and risk-based manner.

Submit a vulnerability

Contact information for follow-up questions 
(optional, but recommended)