esaqa GmbH
  • Home
  • Products
    • Psono Open source password manager for teams
    • Quant Authentication with one line of code
esaqa GmbH
esaqa GmbH

Contact Info

  • esaqa GmbH
  • Tiergartenstr. 13
  • 91247 Vorra, Germany
  • support@esaqa.com

Vulnerability Disclosure Policy

esaqa GmbH takes the security of its products, services, systems, and customers seriously.

Report a security vulnerability Email security@esaqa.com. Reports may be submitted in English or German.

Introduction

We welcome reports from security researchers, customers, partners, and other members of the security community who believe they have discovered a security vulnerability affecting a product or service developed or maintained by esaqa GmbH.

This policy explains how to report a potential vulnerability, what information to include, what you can expect from us, and the principles we follow when coordinating disclosure.

Scope

This policy applies to products, services, websites, applications, and software components developed or maintained by esaqa GmbH, including:

  • Psono Server
  • Psono Web Client
  • Psono browser extensions
  • Psono mobile applications
  • Psono desktop applications
  • Psono SaaS and hosted services operated by esaqa GmbH
  • Quant Authentication Server
  • Quant Authenticator Apps
  • Other software and services published or maintained by esaqa GmbH

This policy does not normally cover vulnerabilities that originate solely in an independently developed third-party dependency. We nevertheless encourage you to contact us when such a dependency affects an esaqa GmbH product. We may coordinate the report with the relevant upstream maintainer or CVE Numbering Authority.

The following are generally outside the scope of this policy:

  • Products, services, or infrastructure not operated or maintained by esaqa GmbH
  • Social-engineering attacks against esaqa GmbH employees, customers, or partners
  • Physical attacks against offices, data centres, employees, or equipment
  • Denial-of-service testing or testing that degrades the availability of a service
  • Automated scanning that generates excessive traffic or affects service stability
  • Reports based solely on missing security headers without a demonstrated security impact
  • Reports based solely on software version identification
  • Reports of publicly known vulnerabilities without evidence that an affected esaqa GmbH product remains vulnerable
  • Reports that require an attacker to have already fully compromised the affected system
  • Spam, phishing, fraud, account disputes, or general support requests

Questions concerning whether a product or activity is in scope may be sent to the security contact below before testing.

Reporting a Vulnerability

Please report suspected security vulnerabilities by email to security@esaqa.com.

Reports may be submitted in English or German.

When possible, include:

  • The affected product, service, component, or URL
  • The affected version or versions
  • A clear description of the vulnerability
  • The security impact and potential attack scenario
  • The prerequisites required to exploit the issue
  • Reproduction instructions or a proof of concept
  • Relevant logs, screenshots, requests, responses, or source-code references
  • Any suggested remediation
  • Whether the vulnerability has been disclosed to anyone else
  • Your preferred name and organization for acknowledgement
  • Whether you would like to be credited publicly
  • Any proposed disclosure date

Please do not include personal data, customer data, credentials, private keys, access tokens, or other sensitive information unless it is strictly necessary to demonstrate the issue. Where sensitive information is necessary, minimize it as much as possible.

Encrypted Reports

Sensitive reports may be encrypted using our published OpenPGP key.

The current key information is published through our security documentation and our security.txt file:

https://esaqa.com/.well-known/security.txt

Before sending encrypted information, verify that the key fingerprint matches the fingerprint published through an esaqa GmbH-controlled channel.

What You Can Expect From Us

After receiving a report, esaqa GmbH will make a reasonable effort to:

  • Acknowledge receipt within three business days
  • Review the report and determine whether additional information is required
  • Provide an initial assessment or status update within ten business days
  • Maintain communication while the report is being investigated
  • Confirm whether the issue is accepted, rejected, already known, or outside our scope
  • Coordinate remediation and disclosure where appropriate
  • Notify the reporter when a fix or advisory is available
  • Credit the reporter when requested and appropriate

Complex vulnerabilities, dependencies on third parties, release constraints, or issues affecting multiple products may require additional time.

A report acknowledgement does not mean that a vulnerability has been confirmed.

Coordinated Disclosure

We ask reporters to give esaqa GmbH a reasonable opportunity to investigate and remediate a vulnerability before publishing technical details.

Unless another timeframe is agreed, we propose a coordinated-disclosure period of up to 90 days from the date on which we receive a sufficiently complete and reproducible report.

The disclosure date may be adjusted where:

  • A fix is available earlier
  • The vulnerability is already being actively exploited
  • The vulnerability has already been disclosed publicly
  • A third-party or upstream maintainer must participate in remediation
  • Deployment requires coordination with customers or service providers
  • Additional time is reasonably necessary to protect users
  • Earlier disclosure is necessary to reduce a significant and immediate risk

We will make reasonable efforts to agree on a disclosure date with the reporter. Where agreement cannot be reached, we ask the reporter to notify us before publication so that we can provide accurate remediation information to affected users.

We may publish an advisory before every supported release or deployment has been updated where the risk of continued nondisclosure is greater than the risk of publication.

CVE Identification

Where appropriate, esaqa GmbH may request, reserve, assign, or coordinate a Common Vulnerabilities and Exposures identifier for a confirmed vulnerability.

The decision to assign a CVE ID depends on factors including:

  • Whether the issue constitutes a vulnerability under the CVE Program rules
  • Whether the affected product falls within esaqa GmbH's CNA scope
  • Whether another CNA has assignment authority
  • Whether the issue has already received a CVE ID
  • Whether the vulnerability will be publicly disclosed
  • Whether multiple reported issues represent one or several distinct vulnerabilities

When esaqa GmbH is not the appropriate CVE Numbering Authority, we may coordinate with the affected upstream project, another CNA, or a CNA of Last Resort.

A CVE ID does not represent a severity rating, endorsement, or guarantee that a report qualifies for a reward.

Security Advisories

Security advisories may include:

  • The CVE ID, where applicable
  • A description of the vulnerability
  • Affected products and versions
  • Fixed versions
  • The potential security impact
  • Available mitigations or workarounds
  • Upgrade instructions
  • Relevant public references
  • Acknowledgement of the reporter
  • A disclosure timeline

Security advisories published by esaqa GmbH are available in our public GitLab repository:

https://gitlab.com/esaqa/esaqa/security-advisories

Researcher Credit

We are happy to acknowledge researchers who report valid vulnerabilities and follow this policy.

Credit may include the reporter's:

  • Name
  • Organization
  • Website or profile link

We will use the credit information agreed with the reporter. Reporters may also remain anonymous.

We may decline or modify acknowledgement where it is misleading, promotional, unlawful, impersonates another party, or contains inappropriate content.

Good-Faith Security Research

esaqa GmbH considers security research to be conducted in good faith when the researcher:

  • Makes a reasonable effort to comply with this policy
  • Tests only to the extent necessary to confirm the vulnerability
  • Avoids harm to users, customers, employees, and third parties
  • Avoids disrupting or degrading products and services
  • Does not access, modify, delete, retain, or disclose data beyond what is necessary to demonstrate the issue
  • Stops testing and notifies us if sensitive data is encountered
  • Does not use a vulnerability for extortion, coercion, or personal gain
  • Does not demand payment as a condition for withholding vulnerability details
  • Gives us a reasonable opportunity to investigate and remediate the issue
  • Complies with applicable law

For research conducted in good faith and in accordance with this policy, esaqa GmbH does not intend to initiate legal action solely because the researcher performed the research or submitted the report.

This statement does not authorize access to third-party systems, customer-controlled deployments, or infrastructure that esaqa GmbH does not own or operate. It also does not bind third parties or prevent esaqa GmbH from taking action in response to malicious, reckless, unlawful, or harmful conduct.

If you are uncertain whether a planned activity is permitted, contact us before proceeding.

Prohibited Activities

Do not:

  • Perform denial-of-service or resource-exhaustion testing
  • Intentionally disrupt the availability of a product or service
  • Access customer accounts or data without explicit authorization
  • Download, copy, alter, delete, or publicly disclose third-party data
  • Plant persistent access mechanisms, malware, or backdoors
  • Conduct phishing, social engineering, or physical-security attacks
  • Attempt to obtain employee credentials
  • Send unsolicited bulk traffic or automated requests that may affect service availability
  • Exploit a vulnerability beyond what is necessary to demonstrate it
  • Publicly disclose an unresolved vulnerability without first making a reasonable effort to coordinate with us
  • Demand payment or threaten disclosure, service disruption, or data release

If testing unexpectedly provides access to sensitive information, stop immediately, do not retain or distribute the information, and notify us.

Customer-Managed Deployments

Some esaqa GmbH products may be deployed and managed by customers on their own infrastructure.

This policy does not authorize testing against a customer-managed deployment unless the customer has given explicit permission. Reports concerning a product vulnerability discovered in an authorized test of a customer deployment may still be submitted to esaqa GmbH.

Do not submit customer data or information that identifies the customer unless this is necessary and you are authorized to do so.

Bug Bounties and Compensation

Unless esaqa GmbH has published separate written terms for a specific bug-bounty program, submission of a vulnerability report does not create an entitlement to payment, compensation, employment, reimbursement, or any other reward.

Any reward offered by esaqa GmbH is voluntary and may be subject to additional eligibility requirements.

Duplicate and Previously Known Reports

A report may be classified as a duplicate when the same underlying vulnerability has already been reported or identified.

Where possible, we will inform the reporter that the issue is already known. We may be unable to share details about another reporter or an embargoed investigation.

Data Protection

Contact information and other personal information submitted with a vulnerability report will be used to:

  • Communicate with the reporter
  • Investigate and remediate the vulnerability
  • Coordinate disclosure
  • Maintain security and audit records
  • Meet legal, regulatory, and CVE Program obligations

Information may be shared with affected upstream maintainers, service providers, customers, CVE Program participants, or authorities where reasonably necessary to investigate or remediate the issue.

Please avoid submitting unnecessary personal information.

No Warranty

This policy describes esaqa GmbH's intended vulnerability-handling process. It does not create a contractual obligation, service-level agreement, guarantee, or warranty.

esaqa GmbH may adapt its response to the circumstances of a particular vulnerability, including its severity, complexity, affected users, active exploitation, legal requirements, and dependencies on third parties.

Changes to This Policy

esaqa GmbH may update this policy when its products, processes, legal obligations, or vulnerability-management responsibilities change.

The version published on the official esaqa GmbH website is the current version.

Last updated: 5 August 2026

Contact

Security vulnerability reports:

security@esaqa.com

General product support requests should be submitted through the normal Psono support channels rather than the security contact.

esaqa GmbH
All products made in Germany with privacy in mind. Security oriented

Links

  • Home
  • Imprint
  • Privacy Policy
  • Vulnerability Disclosure
  • Trust Center

Contact Info

  • esaqa GmbH
    Tiergartenstr. 13
    91247 Vorra
    Germany
  • support@esaqa.com
© 2020 esaqa GmbH. All rights reserved