1. Purpose
This policy governs the coordinated disclosure of security vulnerabilities affecting TQ-Group products and services. Its purpose is to provide security researchers with a clear and reliable framework for good-faith reporting, to structure the assessment and remediation of reported vulnerabilities, and to reduce security risks to customers, users, business partners, and other affected parties as quickly as possible.
TQ-Group welcomes vulnerability reports submitted in accordance with this policy. This policy is limited to coordinated vulnerability disclosure and does not establish a bug bounty program, any entitlement to compensation, or any right to publication or public recognition. Notwithstanding the foregoing, we may, at our discretion, provide a voluntary acknowledgment, in particular by naming the reporting party, provided this is appropriate in the individual case and the reporting party has given prior consent.
2. Scope of Application
This policy applies only to products with digital elements, software, firmware, cloud services, web applications, mobile applications, APIs, domains, and other systems that are developed, operated, or publicly provided by TQ-Group within its own area of responsibility.
The following are out of scope in particular:
3. Authorized Testing Activities
Only good-faith, proportionate, minimally invasive testing activities strictly necessary to verify a suspected vulnerability within the published scope are authorized. Testing must be performed in a manner that does not disrupt production systems or exfiltrate, alter, or disclose data.
Researchers should use their own test accounts, test data, and isolated test environments whenever possible. If personal data, trade secrets, or other confidential information are accessed unintentionally, the testing activities must stop immediately and the incident must be reported without undue delay to the contact point specified in the section "How to Report a Security Vulnerability".
4. Prohibited Activities
The following are prohibited in particular:
5. Coordinated Disclosure
TQ-Group aims for coordinated disclosure after a patch, update, workaround, or other effective risk-reducing measure is available. The objective is to publish in a coordinated manner once affected users can be reasonably protected.
Where a report is valid, a mutually coordinated publication date will generally be sought.
If a third-party vendor is affected, TQ-Group may involve a coordination body, including a CERT or the BSI. Where public risk is high, third parties do not cooperate, or compelling protective interests require it, phased or partial disclosure may be made to the extent necessary for risk mitigation.
6. Safe Harbor
If security researchers act in good faith, test exclusively within the expressly published scope, comply with this policy, promptly and confidentially report vulnerabilities, do not exfiltrate data, do not alter or delete data, do not disrupt services, and do not infringe third-party rights, TQ-Group will regard such activities within its own area of responsibility as authorized. In such cases, TQ-Group will generally not bring civil claims or initiate criminal complaints based on such conduct, provided and for as long as the conduct fully complies with this policy.
This safe harbor does not apply:
This policy binds only TQ-Group and has no binding effect on courts, public authorities, or other third parties. TQ-Group can only limit or waive rights that fall within its own area of control and responsibility.
To the extent legally permissible, TQ-Group will confirm to third parties upon request that good-faith research conduct within the published scope was handled under this policy. No broader waiver of liability, immunity from prosecution, or indemnification is granted.
7. Data Protection and Confidentiality
The confidentiality of reports is subject to applicable legal disclosure, information, or reporting obligations. In particular, TQ-Group may be required to disclose information relating to security incidents, vulnerabilities, or related matters to competent authorities, supervisory bodies, CERTs, or other legally designated entities where required under applicable law, including regulatory requirements such as legislation implementing NIS2. Reports are handled confidentially and shared only with internal functions that require access for triage, remediation, legal assessment, or communications.
Personal data will be processed only in accordance with applicable data protection law. The processing of personal data for the handling and follow-up of reports is based on Art. 6(1)(f) GDPR (legitimate interests in ensuring IT security and investigating and remediating security incidents).
Reporting parties should anonymize or redact personal data, trade secrets, and other confidential information as much as possible. Data that is not necessary for the report must not be retained or disclosed.
8. CVEs and Security Advisory
For valid and disclosable vulnerabilities, TQ-Group will assess whether a CVE reference should be requested or used where appropriate. CVE references will typically be requested via CERT-Bund.
The publication of security advisories may be used to inform and warn users about security advisieries.
9. No Waiver Beyond This Policy
This policy does not constitute a general waiver of rights, consent to any other testing, or any extension of legal authority beyond the expressly described framework. In case of doubt, the security contact point must be consulted before testing takes place. This Policy shall be governed by the laws of the Federal Republic of Germany.
10. Entry into Force and Updates
This policy takes effect upon publication on the TQ-Group website. TQ-Group may amend this policy at any time with future effect; the version published at the time of the relevant research activity shall apply.