Responsible Vulnerability Disclosure

Safety is our top priority

As a manufacturer of smartphones, tablets and IoT devices, we take the security of our products and the protection of our customers very seriously. In line with our obligations under the Cyber Resilience Act (CRA) and the NIS 2 Directive, we have established a structured process for the responsible disclosure of security vulnerabilities.

We welcome your help

We value the work of security researchers, ethical hackers and the security community. If you discover a potential security vulnerability in our products, we would like to work with you to resolve it as quickly as possible.

Affected products

Our Vulnerability Disclosure Programme covers:

  • Smartphones and tablets running our AOSP-based Android firmware
  • IoT devices running Windows 11 IoT Enterprise LTSC 2024
  • Our own hardware components and drivers
  • Firmware and system software
  • Mobile apps and services (where developed directly by us)

Guidelines for responsible disclosure

We ask that you observe the following guidelines:

 

PermittedNot permitted

Security tests should only be carried out on your own, legally acquired devices

Access to or manipulation of other users' data

Use of public test devices and developer kits

Denial-of-service attacks
Responsible research that respects privacyPhysical attacks on our infrastructure
Report vulnerabilities via the official channelSocial engineering targeting employees or customers
 Premature disclosure of security vulnerabilities

Our promise to you

If you report a security vulnerability responsibly, we undertake to:

  • You will receive confirmation of receipt within 3 working days
  • We will keep you informed of the latest developments every 14 days
  • You need not fear any legal consequences, provided you comply with our guidelines
  • Your work will be acknowledged – either by name in our Security Advisories or anonymously, whichever you prefer
  • Together, we will agree on a fair disclosure timeline – 90 days by default

Severity and response times

We categorise security vulnerabilities according to CVSS v4.0 and adhere to the following response times:

 

Severity

CVSS score

Initial analysis

Workaround available

Patch target

Critical

9.0 - 10.0

24 hours

1 working days

30 days

High

7.0 - 8.9

3 working days

3 working days

60 days

Medium

4.0 - 6.9

7 working days

14 working days

90 days

Low

0.1 - 3.9

14 working days

n. a.

120 days

None

0.0

n. a.

n. a.

n. a.

How to report a security vulnerability

  1. Fill in our reporting form (link below)

  2. Encrypt sensitive information using our PGP key (optional but recommended)

  3. Include all relevant details: proof of concept, logs, screenshots

  4. Wait for our confirmation

 

Report a security vulnerability: Download the report

Contact:  security.txt

Frequently asked questions?

Do you offer a bug bounty programme?

We do not currently offer a financial bug bounty programme, but we reserve the right to do so in the future.

 

How long does it take to process a report?

The time taken to resolve an issue depends on the severity of the vulnerability. Critical vulnerabilities are usually resolved within two to four weeks, whilst less critical issues may take up to twelve weeks. We will keep you informed of progress throughout the entire process.

 

Can I remain anonymous?

Yes, you can also report security vulnerabilities anonymously. However, providing contact details makes communication much easier should we have any queries regarding the reported vulnerability. Your data will, of course, be treated confidentially and will not be shared without your consent.

 

In which languages can I submit reports?

We accept reports in German and English. If you wish to communicate in another language, please contact us in advance so that we can find a solution.

 

Is there a Hall of Fame?

Security researchers who help us improve our products can be listed in our Security Hall of Fame upon request.

 

Where can I find the security advisories?

Published security advisories and patches can be found in our Security Bulletin.