Vulnerability disclosure policy
vploq · Effective date: 17 September 2026 · Version 1.0
If you believe you have found a security vulnerability in the vploq App, the vploq Device, its firmware, or any service we operate, we want to hear about it. This page tells you how to reach us, what we ask of you, and what we undertake to do in return.
How to report
Email info@vploq.com with security in the
subject line.
Reporting costs nothing, requires no prior request and no account, and we do not ask you for your name, your address or any other personal information in order to accept a report. If you would rather stay anonymous, say so and send the report from an address you do not mind us seeing; we will work with what we are given.
This contact is also published in machine-readable form, in the format defined
by RFC 9116, at
/.well-known/security.txt.
What to include
Send us as much of this as you have. A report we cannot reproduce is a report we cannot fix.
- What the problem is, and what an attacker could do with it.
- The product, service or address affected, and the version if you know it — for a Device, the firmware version shown against it in the App.
- The steps to reproduce it, in order.
- Anything that helps: a proof-of-concept, a packet capture, a log excerpt, a screenshot.
- How you would like to be credited, if you would like to be credited.
Write in English. We will answer in English.
What we undertake to do
| Stage | What we do | When |
|---|---|---|
| Acknowledgement | We confirm to you that your report has arrived and has been read by a person | Within five (5) working days of receipt |
| Triage | We tell you whether we have reproduced the issue, and our initial view of its severity | Within ten (10) working days of acknowledgement |
| Progress | We tell you where the fix has got to, whether or not there is news | At least every thirty (30) days until the report is closed |
| Resolution | We tell you what we changed, and when the fix reaches users | On closing the report |
We will keep you informed for as long as the report is open. If we decide not to act on a report, we will tell you that, and why, rather than letting it go quiet.
What we ask of you
We ask you to give us a reasonable opportunity to fix the problem before you describe it publicly. We do not impose a fixed embargo and we will not ask you to stay silent indefinitely; if we are taking too long, tell us, and we will agree a date with you.
While you are investigating, please:
- Work only against your own account and your own Device.
- Do not access, modify, copy or delete anybody else's data. If you come across someone else's personal data by accident, stop, and tell us what you saw so that we can assess it — do not keep a copy.
- Do not degrade the service for anybody else: no denial-of-service testing, no brute forcing, no spam, no social engineering of our staff or our suppliers, no physical intrusion.
- Do not use an attack you have found to reach further into our systems than is needed to demonstrate it.
Safe harbour
If you follow this policy in good faith, we will treat your work as authorised research. We will not bring a claim against you, and we will not report you to a law-enforcement authority, in respect of that research. If a third party brings a claim against you for work you did within this policy, tell us and we will make our authorisation clear.
This assurance is ours to give and covers only us. It cannot bind anybody else, and it does not cover conduct outside this policy.
What is in scope
- The vploq App for iOS, macOS, Android and Windows.
- The vploq Device and its firmware.
- Services we operate:
docs.vploq.com,download.vploq.com, and our coordination and update APIs.
Out of scope: the vploq.com storefront, which is hosted by Shopify, and any
other third-party service we merely use — those have their own disclosure
programmes; findings that
consist only of the output of an automated scanner with no demonstrated impact;
missing security headers, TLS configuration preferences and similar hardening
opinions with no demonstrated impact; and reports about software we neither
write nor operate.
Rewards
We do not run a paid bug-bounty programme. We will credit you by name or handle, with your permission, once a fix has reached users.
Security updates
Security fixes for the Device reach it as a signed firmware update, verified by the Device before it is installed. Fixes for the App are published through the platform app stores and, on Windows, as a signed installer.
The minimum period for which security updates will be provided for the Device is not yet published. No vploq Device has been supplied to a customer, and the period will be published here — and in the statement of compliance accompanying the product — before the first one is. We would rather publish nothing here than publish a commitment we have not made.
If your report concerns personal data
A vulnerability that has exposed personal data is also a matter for our privacy policy. Say so in your report and we will treat it under both.