DocuWare Vulnerability Disclosure

Our customers trust DocuWare with their documents and the business processes built on them. Keeping that information secure is fundamental to earning and keeping that trust, and we know that no software is free of security vulnerabilities. This page explains how DocuWare handles security vulnerabilities, how you can report one, and the commitments we make when we respond.

How DocuWare handles security vulnerabilities

DocuWare practices coordinated vulnerability disclosure. When a vulnerability is reported to us or discovered by our own teams, we validate it, assess its impact, develop and ship a fix, and coordinate any public disclosure. Published disclosures are listed on our coordinated disclosures page.

We believe vulnerability disclosure is a two-way street: reporters give vendors a fair chance to fix an issue before publishing, and vendors respond within committed timelines. The timelines below are the standard we hold ourselves to.

Reporting a security issue

If you believe you have found a security vulnerability in a DocuWare product or service, or if you as a customer are under attack, we want to hear from you.

Follow this link to report a security vulnerability. The page documents the program scope, the rules of engagement, and all reporting channels available, including a form if you wish to report anonymously.

Regardless of how you contact us, our guide on writing a quality vulnerability report explains what a report needs so we can validate and fix the issue quickly.

DocuWare will not pursue legal action against researchers who act in good faith within the program's scope and rules of engagement.

Response timelines

Once a report is validated, we try to hold the following timelines:

Case Goal
Validated, verified, and actively exploited vulnerability A patch is made available within 14 calendar days.
Corporate security incident Remediated within 30 calendar days.
Vulnerability disclosure report Published within 90 calendar days.

Actively exploited vulnerabilities put customers at risk every day they remain unfixed, which is why they carry our most aggressive timeline. For vulnerabilities that are valid but not under active exploitation, remediation is prioritized by severity.

The coordinated vulnerability disclosure process is considered complete under the following conditions.