
Email has been sent
We'll get back to you shortly.
Project Q believes that vulnerability disclosure is a two-way street, where both service providers and security researchers must act responsibly. We are committed to help ensure the confidentiality and security of our customers’ information and reporters’ identities.
The security vulnerability disclosure policy helps in risk reduction and improves security, confidentiality, and privacy for not only Project Q and its customers, but for anyone affected directly or indirectly. We aim to resolve issues within 90 days – however, when deemed reasonable, this deadline may be extended at the sole discretion of the company.
Overview
At Project Q, we welcome reports of security vulnerabilities in our products and services. We are committed to reviewing every report, and to understand and resolve the issue. This policy details how to get in touch with us, what to send, how reports are handled, what you can expect in return.
Scope
We accept reports for currently listed Project Q products. Each vulnerability report is handled and reviewed by a team, consisting of our own employees or external parties, coordinated through the Information Security team and its CISO.
This reporting channel is intended for:
- Vulnerabilities in our products and product components
- Security-relevant bugs affecting the confidentiality, integrity or availability of our products or services
- Misconfigurations or insecure default settings
- Vulnerabilities in our publicly reachable web applications or interfaces, where they are attributable to us
Out of scope, as a rule, are third-party products, services operated by external providers, and systems outside our area of responsibility. For vulnerabilities in third-party products, please contact the respective manufacturer or operator.
What reports should include
To let us assess your report quickly, please include as much of the following as you can:
- Affected product
- Affected version
- Description of the vulnerability
- Potential impact
- Steps to reproduce
- Screenshots or log extracts (where available)
- A contact option for follow-up questions (unless you are reporting anonymously)
If appropriate, we will request additional information from the reporter.
How to report
Please use one of the following channels for security reports:
- Email: [email protected]
- Web form: https://www.project-q.ai/vulnerability-disclosure
Please do not use this channel for general support requests.
Reporting anonymously
You may report anonymously. If you would rather not contact us directly, you can submit your report through Germany's national CSIRT, CERT-Bund at the Federal Office for Information Security (BSI), which acts as a coordinator for coordinated vulnerability disclosure and can pass your report to us:
- Email: [email protected]
- Web form: https://www.bsi.bund.de/Security-Contact
Please do not use this channel for general support requests.
Accepted languages
We accept reports in German (de) and English (en).
What you can expect from us
We will acknowledge receipt of your report within three business days (reference calendar and time for Germany). If a deadline is due to expire on a weekend or falls on a German public holiday, the deadline will be moved to the next workday.
After receiving a report, we will carry out an initial assessment and let you know our findings, normally within ten business days. Where the report is valid and the vulnerability in scope for our products, we will prioritise the issue, work with the responsible product team on a remediation, and keep you informed of progress at key milestones. We will notify you once the issue is resolved.
We ask that you give us reasonable time to remediate before disclosing the issue publicly, and that you coordinate the timing of any public disclosure with us.
Legal notice and safe harbour
This reporting channel serves the coordinated submission of security reports. It does not constitute authorisation for invasive testing, disruption of operations, or access to data that is not yours or not released for testing.
We will not pursue or support legal action against researchers who, in good faith:
- act within the scope described above,
- avoid privacy violations, degradation of service, and destruction or modification of data,
- access only the minimum data necessary to demonstrate the issue, and
- give us reasonable time to remediate before any public disclosure.
If in doubt, contact us before testing.
Machine-readable contact information
We also publish our security contact information in machine-readable form, in line with RFC 9116, at https://project-q.ai/.well-known/security.txt

