esaqa GmbH takes the security of its products, services, systems, and customers seriously.
We welcome reports from security researchers, customers, partners, and other members of the security community who believe they have discovered a security vulnerability affecting a product or service developed or maintained by esaqa GmbH.
This policy explains how to report a potential vulnerability, what information to include, what you can expect from us, and the principles we follow when coordinating disclosure.
This policy applies to products, services, websites, applications, and software components developed or maintained by esaqa GmbH, including:
This policy does not normally cover vulnerabilities that originate solely in an independently developed third-party dependency. We nevertheless encourage you to contact us when such a dependency affects an esaqa GmbH product. We may coordinate the report with the relevant upstream maintainer or CVE Numbering Authority.
The following are generally outside the scope of this policy:
Questions concerning whether a product or activity is in scope may be sent to the security contact below before testing.
Please report suspected security vulnerabilities by email to security@esaqa.com.
Reports may be submitted in English or German.
When possible, include:
Please do not include personal data, customer data, credentials, private keys, access tokens, or other sensitive information unless it is strictly necessary to demonstrate the issue. Where sensitive information is necessary, minimize it as much as possible.
Sensitive reports may be encrypted using our published OpenPGP key.
The current key information is published through our security documentation and our security.txt file:
https://esaqa.com/.well-known/security.txt
Before sending encrypted information, verify that the key fingerprint matches the fingerprint published through an esaqa GmbH-controlled channel.
After receiving a report, esaqa GmbH will make a reasonable effort to:
Complex vulnerabilities, dependencies on third parties, release constraints, or issues affecting multiple products may require additional time.
A report acknowledgement does not mean that a vulnerability has been confirmed.
We ask reporters to give esaqa GmbH a reasonable opportunity to investigate and remediate a vulnerability before publishing technical details.
Unless another timeframe is agreed, we propose a coordinated-disclosure period of up to 90 days from the date on which we receive a sufficiently complete and reproducible report.
The disclosure date may be adjusted where:
We will make reasonable efforts to agree on a disclosure date with the reporter. Where agreement cannot be reached, we ask the reporter to notify us before publication so that we can provide accurate remediation information to affected users.
We may publish an advisory before every supported release or deployment has been updated where the risk of continued nondisclosure is greater than the risk of publication.
Where appropriate, esaqa GmbH may request, reserve, assign, or coordinate a Common Vulnerabilities and Exposures identifier for a confirmed vulnerability.
The decision to assign a CVE ID depends on factors including:
When esaqa GmbH is not the appropriate CVE Numbering Authority, we may coordinate with the affected upstream project, another CNA, or a CNA of Last Resort.
A CVE ID does not represent a severity rating, endorsement, or guarantee that a report qualifies for a reward.
Security advisories may include:
Security advisories published by esaqa GmbH are available in our public GitLab repository:
We are happy to acknowledge researchers who report valid vulnerabilities and follow this policy.
Credit may include the reporter's:
We will use the credit information agreed with the reporter. Reporters may also remain anonymous.
We may decline or modify acknowledgement where it is misleading, promotional, unlawful, impersonates another party, or contains inappropriate content.
esaqa GmbH considers security research to be conducted in good faith when the researcher:
For research conducted in good faith and in accordance with this policy, esaqa GmbH does not intend to initiate legal action solely because the researcher performed the research or submitted the report.
This statement does not authorize access to third-party systems, customer-controlled deployments, or infrastructure that esaqa GmbH does not own or operate. It also does not bind third parties or prevent esaqa GmbH from taking action in response to malicious, reckless, unlawful, or harmful conduct.
If you are uncertain whether a planned activity is permitted, contact us before proceeding.
Do not:
If testing unexpectedly provides access to sensitive information, stop immediately, do not retain or distribute the information, and notify us.
Some esaqa GmbH products may be deployed and managed by customers on their own infrastructure.
This policy does not authorize testing against a customer-managed deployment unless the customer has given explicit permission. Reports concerning a product vulnerability discovered in an authorized test of a customer deployment may still be submitted to esaqa GmbH.
Do not submit customer data or information that identifies the customer unless this is necessary and you are authorized to do so.
Unless esaqa GmbH has published separate written terms for a specific bug-bounty program, submission of a vulnerability report does not create an entitlement to payment, compensation, employment, reimbursement, or any other reward.
Any reward offered by esaqa GmbH is voluntary and may be subject to additional eligibility requirements.
A report may be classified as a duplicate when the same underlying vulnerability has already been reported or identified.
Where possible, we will inform the reporter that the issue is already known. We may be unable to share details about another reporter or an embargoed investigation.
Contact information and other personal information submitted with a vulnerability report will be used to:
Information may be shared with affected upstream maintainers, service providers, customers, CVE Program participants, or authorities where reasonably necessary to investigate or remediate the issue.
Please avoid submitting unnecessary personal information.
This policy describes esaqa GmbH's intended vulnerability-handling process. It does not create a contractual obligation, service-level agreement, guarantee, or warranty.
esaqa GmbH may adapt its response to the circumstances of a particular vulnerability, including its severity, complexity, affected users, active exploitation, legal requirements, and dependencies on third parties.
esaqa GmbH may update this policy when its products, processes, legal obligations, or vulnerability-management responsibilities change.
The version published on the official esaqa GmbH website is the current version.
Last updated: 5 August 2026
Security vulnerability reports:
General product support requests should be submitted through the normal Psono support channels rather than the security contact.

