Safety is our top priority
As a manufacturer of smartphones, tablets and IoT devices, we take the security of our products and the protection of our customers very seriously. In line with our obligations under the Cyber Resilience Act (CRA) and the NIS 2 Directive, we have established a structured process for the responsible disclosure of security vulnerabilities.
Affected products
Our Vulnerability Disclosure Programme covers:
- Smartphones and tablets running our AOSP-based Android firmware
- IoT devices running Windows 11 IoT Enterprise LTSC 2024
- Our own hardware components and drivers
- Firmware and system software
- Mobile apps and services (where developed directly by us)
Guidelines for responsible disclosure
We ask that you observe the following guidelines:
| Permitted | Not permitted |
Security tests should only be carried out on your own, legally acquired devices | Access to or manipulation of other users' data |
Use of public test devices and developer kits | Denial-of-service attacks |
| Responsible research that respects privacy | Physical attacks on our infrastructure |
| Report vulnerabilities via the official channel | Social engineering targeting employees or customers |
| Premature disclosure of security vulnerabilities |
Our promise to you
If you report a security vulnerability responsibly, we undertake to:
- You will receive confirmation of receipt within 3 working days
- We will keep you informed of the latest developments every 14 days
- You need not fear any legal consequences, provided you comply with our guidelines
- Your work will be acknowledged – either by name in our Security Advisories or anonymously, whichever you prefer
- Together, we will agree on a fair disclosure timeline – 90 days by default
Severity and response times
We categorise security vulnerabilities according to CVSS v4.0 and adhere to the following response times:
Severity | CVSS score | Initial analysis | Workaround available | Patch target |
Critical | 9.0 - 10.0 | 24 hours | 1 working days | 30 days |
High | 7.0 - 8.9 | 3 working days | 3 working days | 60 days |
Medium | 4.0 - 6.9 | 7 working days | 14 working days | 90 days |
Low | 0.1 - 3.9 | 14 working days | n. a. | 120 days |
None | 0.0 | n. a. | n. a. | n. a. |
How to report a security vulnerability
Fill in our reporting form (link below)
Encrypt sensitive information using our PGP key (optional but recommended)
Include all relevant details: proof of concept, logs, screenshots
Wait for our confirmation
Report a security vulnerability: Download the report
Contact: security.txt
Frequently asked questions?
Do you offer a bug bounty programme?
We do not currently offer a financial bug bounty programme, but we reserve the right to do so in the future.
How long does it take to process a report?
The time taken to resolve an issue depends on the severity of the vulnerability. Critical vulnerabilities are usually resolved within two to four weeks, whilst less critical issues may take up to twelve weeks. We will keep you informed of progress throughout the entire process.
Can I remain anonymous?
Yes, you can also report security vulnerabilities anonymously. However, providing contact details makes communication much easier should we have any queries regarding the reported vulnerability. Your data will, of course, be treated confidentially and will not be shared without your consent.
In which languages can I submit reports?
We accept reports in German and English. If you wish to communicate in another language, please contact us in advance so that we can find a solution.
Is there a Hall of Fame?
Security researchers who help us improve our products can be listed in our Security Hall of Fame upon request.
Where can I find the security advisories?
Published security advisories and patches can be found in our Security Bulletin.


