Report a vulnerability

If you believe you have found a security vulnerability in one of our products, please contact us.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Email has been sent

We'll get back to you shortly.

Project Q believes that vulnerability disclosure is a two-way street, where both service providers and security researchers must act responsibly. We are committed to help ensure the confidentiality and security of our customers’ information and reporters’ identities.

The security vulnerability disclosure policy helps in risk reduction and improves security, confidentiality, and privacy for not only Project Q and its customers, but for anyone affected directly or indirectly. We aim to resolve issues within 90 days – however, when deemed reasonable, this deadline may be extended at the sole discretion of the company.

Overview

At Project Q, we welcome reports of security vulnerabilities in our products and services. We are committed to reviewing every report, and to understand and resolve the issue. This policy details how to get in touch with us, what to send, how reports are handled, what you can expect in return.

Scope

We accept reports for currently listed Project Q products. Each vulnerability report is handled and reviewed by a team, consisting of our own employees or external parties, coordinated through the Information Security team and its CISO.

This reporting channel is intended for:

  • Vulnerabilities in our products and product components
  • Security-relevant bugs affecting the confidentiality, integrity or availability of our products or services
  • Misconfigurations or insecure default settings
  • Vulnerabilities in our publicly reachable web applications or interfaces, where they are attributable to us

Out of scope, as a rule, are third-party products, services operated by external providers, and systems outside our area of responsibility. For vulnerabilities in third-party products, please contact the respective manufacturer or operator.

What reports should include

To let us assess your report quickly, please include as much of the following as you can:

  • Affected product
  • Affected version
  • Description of the vulnerability
  • Potential impact
  • Steps to reproduce
  • Screenshots or log extracts (where available)
  • A contact option for follow-up questions (unless you are reporting anonymously)

If appropriate, we will request additional information from the reporter.

How to report

Please use one of the following channels for security reports:

Please do not use this channel for general support requests.

Reporting anonymously

You may report anonymously. If you would rather not contact us directly, you can submit your report through Germany's national CSIRT, CERT-Bund at the Federal Office for Information Security (BSI), which acts as a coordinator for coordinated vulnerability disclosure and can pass your report to us:

Please do not use this channel for general support requests.

Accepted languages

We accept reports in German (de) and English (en).

What you can expect from us

We will acknowledge receipt of your report within three business days (reference calendar and time for Germany). If a deadline is due to expire on a weekend or falls on a German public holiday, the deadline will be moved to the next workday.

After receiving a report, we will carry out an initial assessment and let you know our findings, normally within ten business days. Where the report is valid and the vulnerability in scope for our products, we will prioritise the issue, work with the responsible product team on a remediation, and keep you informed of progress at key milestones. We will notify you once the issue is resolved.

We ask that you give us reasonable time to remediate before disclosing the issue publicly, and that you coordinate the timing of any public disclosure with us.

Legal notice and safe harbour

This reporting channel serves the coordinated submission of security reports. It does not constitute authorisation for invasive testing, disruption of operations, or access to data that is not yours or not released for testing.

We will not pursue or support legal action against researchers who, in good faith:

  • act within the scope described above,
  • avoid privacy violations, degradation of service, and destruction or modification of data,
  • access only the minimum data necessary to demonstrate the issue, and
  • give us reasonable time to remediate before any public disclosure.

If in doubt, contact us before testing.

Machine-readable contact information

We also publish our security contact information in machine-readable form, in line with RFC 9116, at https://project-q.ai/.well-known/security.txt

Ready to connect your network?

Your team inspects every line, owns every deployment, and answers to no foreign vendor.

Dry grassy landscape with scattered pine trees and brown hills in the background under clear sky.Dry grassy field with scattered pine trees and rocky hills under clear sky.