Vulnerability Management

Vulnerability disclosure policy

G DATA CyberDefense AG and its subsidiaries ("G Data") follow a responsible disclosure process for potential vulnerabilities and software anomalies (bugs). This includes vulnerabilities and bugs in computer and mobile software that is produced by G DATA, as well as vulnerabilities in online services, domains and websites that are maintained by G DATA.

During the investigation and mitigation of discovered vulnerabilities, G DATA follows the Vulnerability Handling Process. Engaging the appropriate personnel and resources at the right time to ensure that each reported vulnerability is validated and resolved. The process is considered complete when a mitigation solution has been developed and deployed and all relevant parties have been informed. For non-confirmed vulnerabilities, the process is considered complete once the reporter has been notified of the investigation results. In certain cases, the process may end without creating and deploying a mitigation solution – G DATA may choose to publish only the necessary information and mitigation instructions rather than implementing a fix.

Good communication is important for vulnerability reporting. We encourage reporters to provide us with at least one valid contact option (preferably an email address) for any queries.

We emphasize clearly that all involved parties must treat each other with respect and that unlawful behavior within the EU, such as discrimination, sexism, racism, Nazism, glorification of violence, pornography, insults, defamation and slander, will not be tolerated.

This document only sketches the outlines and main focus of the disclosure and privacy policies of G DATA. Please visit our Vulnerability Disclosure Policy for comprehensive and complete information. Our Privacy Policy can be found here.

Contact information - how to submit reports

Vulnerability reports should be submitted via the special webform that is available here. Alternatively, vulnerability reports may be sent via e-mail to this address: security@gdata.de.

Response times

Every vulnerability report is acknowledged within 7 days from the submission date. A unique tracking number is assigned to each report, and this number is shared with the vulnerability reporter.

Within the next 14 days, the reporter receives a notification whether a reported vulnerability is confirmed or not. If a vulnerability is already known to G DATA, the report is still going to be processed, and the reporter gets an appropriate notification.

In case a vulnerability cannot be reproduced in-house, G DATA may ask the reporter for additional details and files or extend the time to confirm a vulnerability. Notifications will be sent to reporters only if they provide valid contact information. This is not possible for anonymous submissions. For details, see the "Anonymous reporting" section of this document.

Anonymous reporting

Communication between G DATA and vulnerability reporters is important. However, each report can also be submitted anonymously, without specifying the contact information.

Please note that anonymous reports can only be processed to a limited extent due to missing contact options to request additional technical details. In addition, if no contact information is provided, G DATA will not be able to acknowledge received reports and will not be able to send gifts of appreciation for confirmed vulnerabilities.

Encrypted communication

Encryption is not required but recommended for vulnerability reporting. We recommend using PGP encryption. Details can be found in our Vulnerability Disclosure Policy.