Report a Security Vulnerability

CRA Icon

 

The security of our products is our highest priority. If you have discovered a potential security vulnerability in a TQ product, we encourage you to report it to us. By following a responsible disclosure process (Coordinated Vulnerability Disclosure), you help us analyze vulnerabilities promptly and take appropriate measures to protect our customers.

How we handle Vulnerability Reports

TQ-Group follows the process below for vulnerability reports:

  1. Acknowledgement of receipt within 5 business days.
  2. Initial technical response within 10 business days, indicating whether the report appears plausible, whether additional information is needed, or whether the issue is not reproducible.
  3. Risk assessment and prioritization considering exploitability, severity, reach, supply-chain relevance, and available mitigations.
  4. Decision on remediation, mitigation, workaround, monitoring, or documented non-remediation with reasons.
  5. Coordinated disclosure.

These timelines are target service levels for the initial response only. Time to remediation depends in particular on severity, complexity, availability of safe mitigations, supply-chain dependencies, and regulatory requirements.

How to Report a Security Vulnerability

Vulnerability reports must be submitted exclusively to TQ-Group’s central security contact point:

  • Email: productsecurity@tq-group.com
  • PGP key: Download
  • PGP fingerprint: 19BA 6177 FCDA 9ACC 75C9 99F8 D673 A456 595A 8DED

Reports may also be submitted anonymously or under a pseudonym. In such cases, the ability to communicate and coordinate may be limited.

Report a Security Vulnerability

To help us assess your report efficiently, please provide as much of the following information as possible:

  • affected product, service, URL, API, or component.
  • affected version, firmware version, build, or configuration.
  • technical description of the vulnerability.
  • reproduction steps.
  • proof of concept or equivalent technical evidence, if available.
  • required privileges or preconditions.
  • observed and potential impact.
  • date and time of discovery.
  • contact details for follow-up questions.

Where possible, reports should additionally include a CVSS assessment, log excerpts, redacted screenshots, references to affected third parties, and suggestions for coordinated disclosure.

Security Advisory

Here we publish information about known security vulnerabilities affecting TQ products, including available security updates and recommended mitigation measures.

There are currently no published Security Advisories for TQ products. This section will be updated regularly as new security-related information becomes available.

Coordinated Vulnerability Disclosure Policy

Transparency builds trust. Learn how we assess, handle, and responsibly disclose reported security vulnerabilities in collaboration with security researchers.

 
38