DocuWare Vulnerability Disclosure
Our customers trust DocuWare with their documents and the business processes built on them. Keeping that information secure is fundamental to earning and keeping that trust, and we know that no software is free of security vulnerabilities. This page explains how DocuWare handles security vulnerabilities, how you can report one, and the commitments we make when we respond.
How DocuWare handles security vulnerabilities
DocuWare practices coordinated vulnerability disclosure. When a vulnerability is reported to us or discovered by our own teams, we validate it, assess its impact, develop and ship a fix, and coordinate any public disclosure. Published disclosures are listed on our coordinated disclosures page.
We believe vulnerability disclosure is a two-way street: reporters give vendors a fair chance to fix an issue before publishing, and vendors respond within committed timelines. The timelines below are the standard we hold ourselves to.
Reporting a security issue
If you believe you have found a security vulnerability in a DocuWare product or service, or if you as a customer are under attack, we want to hear from you.
Follow this link to report a security vulnerability. The page documents the program scope, the rules of engagement, and all reporting channels available, including a form if you wish to report anonymously.
Regardless of how you contact us, our guide on writing a quality vulnerability report explains what a report needs so we can validate and fix the issue quickly.
DocuWare will not pursue legal action against researchers who act in good faith within the program's scope and rules of engagement.
Response timelines
Once a report is validated, we try to hold the following timelines:
| Case | Goal |
|---|---|
| Validated, verified, and actively exploited vulnerability | A patch is made available within 14 calendar days. |
| Corporate security incident | Remediated within 30 calendar days. |
| Vulnerability disclosure report | Published within 90 calendar days. |
Actively exploited vulnerabilities put customers at risk every day they remain unfixed, which is why they carry our most aggressive timeline. For vulnerabilities that are valid but not under active exploitation, remediation is prioritized by severity.
The coordinated vulnerability disclosure process is considered complete under the following conditions.
- The indications of the vulnerability report are unfounded or out of scope as defined in our reporting guidelines.
- Any communication that is not concerning vulnerability reports will be closed without any response. This includes advertisement, spam, etc.
- The reporter has failed to respond to technical or content-related queries for at least 30 days and therefore the corresponding vulnerability report can only be processed to a limited extent or not at all.
- A valid reported vulnerability has been mitigated or fixed and has been publicly disclosed.
- A valid reported vulnerability has been publicly disclosed, yet it can no longer be assumed that it will be mitigated or fixed. This path will only be chosen in exceptional cases and in close consultation with our corresponding national CSIRT.