Security Vulnerability Disclosure Policy (VDP) | V-ZUG Österreich

Security Vulnerability Disclosure Policy (VDP)

Security Vulnerability Disclosure Policy (VDP)

The security of customer data and the reliability of our products and services are of the utmost importance to V-ZUG. Therefore, we strive to develop and provide products and services with the highest level of security and reliability. This policy describes the V-ZUG approach to soliciting and receiving reports of potential security vulnerabilities and bugs in its products and services.

V-ZUG recognizes the value of contributions from the security researcher community and greatly appreciates the efforts of the reporting party in identifying security vulnerabilities or bugs.

 


 

Scope

Customers, users, researchers, partners, and all other individuals who interact with V-ZUG's products and publicly accessible services are encouraged to report any security vulnerabilities and bugs they discover in these products and services.

The following are explicitly out of scope and should not be tested or reported under this policy:

  • Social engineering attacks (e.g. phishing, pretexting) targeting V-ZUG employees or customers
  • Physical security attacks against V-ZUG facilities or hardware
  • Denial-of-service (DoS/DDoS) attacks
  • Vulnerabilities in third-party services or products not directly controlled by V-ZUG
  • Findings from automated scanning tools without demonstrated exploitability

 


 

Legal Protection

We consider activities that comply with this policy to be authorized access and will not take legal action against you. Should legal action be taken against you by a third party and you have complied with this policy, we will take the necessary steps to inform the authorities that your actions were in accordance with this policy.

We ask that you:

  • Act in good faith and avoid privacy violations, data destruction, or service disruption
  • Do not access, modify, or delete data beyond what is necessary to demonstrate the vulnerability
  • Do not publicly disclose the vulnerability before V-ZUG has had the opportunity to address it

 


 

How to Report Security Vulnerabilities

If you have discovered a potential security vulnerability or bug in a V-ZUG product or service, please report it to our security team via:

E-Mail: [email protected]

Please include the following information in your report:

  • A description of the vulnerability and its potential impact
  • The affected product, service, or component (including version if known)
  • Step-by-step instructions to reproduce the issue
  • Any supporting material (screenshots, proof-of-concept code, logs)

 


 

Coordinated Vulnerability Disclosure

V-ZUG follows the principle of Coordinated Vulnerability Disclosure (CVD). This means:

  1. Acknowledgement — We will acknowledge receipt of your report within 72 hours.
  2. Assessment — We will assess the reported vulnerability and provide an initial evaluation within 10 business days.
  3. Remediation — We will work to develop and deploy a fix as quickly as possible, depending on the complexity and severity of the issue.
  4. Notification — We will inform you once the vulnerability has been resolved and agree with you on a reasonable public disclosure timeline (typically 90 days from initial report).

Where a vulnerability is being actively exploited or poses a critical risk, V-ZUG may coordinate disclosure with the relevant national authorities or CERT organisations (e.g. ENISA, CERT-Bund, Switch CERT) in accordance with the EU Cyber Resilience Act (CRA), Art. 13 & 14.

 


 

Bug Bounty

V-ZUG currently does not operate a paid bug bounty programme. However, we genuinely appreciate responsible disclosures and may acknowledge your contribution publicly (with your consent) upon resolution of the reported issue.