# Vulnerability disclosure policy

**vploq** · Effective date: 17 September 2026 · Version 1.0

If you believe you have found a security vulnerability in the vploq App, the
vploq Device, its firmware, or any service we operate, we want to hear about
it. This page tells you how to reach us, what we ask of you, and what we
undertake to do in return.

## How to report

Email [**info@vploq.com**](mailto:info@vploq.com) with `security` in the
subject line.

Reporting costs nothing, requires no prior request and no account, and we do
not ask you for your name, your address or any other personal information in
order to accept a report. If you would rather stay anonymous, say so and send
the report from an address you do not mind us seeing; we will work with what we
are given.

This contact is also published in machine-readable form, in the format defined
by RFC 9116, at
[`/.well-known/security.txt`](/.well-known/security.txt).

## What to include

Send us as much of this as you have. A report we cannot reproduce is a report
we cannot fix.

- What the problem is, and what an attacker could do with it.
- The product, service or address affected, and the version if you know it —
  for a Device, the firmware version shown against it in the App.
- The steps to reproduce it, in order.
- Anything that helps: a proof-of-concept, a packet capture, a log excerpt, a
  screenshot.
- How you would like to be credited, if you would like to be credited.

Write in English. We will answer in English.

## What we undertake to do

| Stage | What we do | When |
| --- | --- | --- |
| Acknowledgement | We confirm to you that your report has arrived and has been read by a person | Within **five (5) working days** of receipt |
| Triage | We tell you whether we have reproduced the issue, and our initial view of its severity | Within **ten (10) working days** of acknowledgement |
| Progress | We tell you where the fix has got to, whether or not there is news | At least every **thirty (30) days** until the report is closed |
| Resolution | We tell you what we changed, and when the fix reaches users | On closing the report |

We will keep you informed for as long as the report is open. If we decide not
to act on a report, we will tell you that, and why, rather than letting it go
quiet.

## What we ask of you

We ask you to give us a reasonable opportunity to fix the problem before you
describe it publicly. We do not impose a fixed embargo and we will not ask you
to stay silent indefinitely; if we are taking too long, tell us, and we will
agree a date with you.

While you are investigating, please:

- Work only against your own account and your own Device.
- Do not access, modify, copy or delete anybody else's data. If you come across
  someone else's personal data by accident, stop, and tell us what you saw so
  that we can assess it — do not keep a copy.
- Do not degrade the service for anybody else: no denial-of-service testing, no
  brute forcing, no spam, no social engineering of our staff or our suppliers,
  no physical intrusion.
- Do not use an attack you have found to reach further into our systems than is
  needed to demonstrate it.

## Safe harbour

If you follow this policy in good faith, we will treat your work as authorised
research. We will not bring a claim against you, and we will not report you to
a law-enforcement authority, in respect of that research. If a third party
brings a claim against you for work you did within this policy, tell us and we
will make our authorisation clear.

This assurance is ours to give and covers only us. It cannot bind anybody else,
and it does not cover conduct outside this policy.

## What is in scope

- The vploq App for iOS, macOS, Android and Windows.
- The vploq Device and its firmware.
- Services we operate: `docs.vploq.com`, `download.vploq.com`, and our
  coordination and update APIs.

Out of scope: the `vploq.com` storefront, which is hosted by Shopify, and any
other third-party service we merely use — those have their own disclosure
programmes; findings that
consist only of the output of an automated scanner with no demonstrated impact;
missing security headers, TLS configuration preferences and similar hardening
opinions with no demonstrated impact; and reports about software we neither
write nor operate.

## Rewards

We do not run a paid bug-bounty programme. We will credit you by name or
handle, with your permission, once a fix has reached users.

## Security updates

Security fixes for the Device reach it as a signed firmware update, verified by
the Device before it is installed. Fixes for the App are published through the
platform app stores and, on Windows, as a signed installer.

The minimum period for which security updates will be provided for the Device
is not yet published. No vploq Device has been supplied to a customer, and the
period will be published here — and in the statement of compliance accompanying
the product — before the first one is. We would rather publish nothing here
than publish a commitment we have not made.

## If your report concerns personal data

A vulnerability that has exposed personal data is also a matter for our
[privacy policy](/privacy). Say so in your report and we will treat it under
both.
