Report a Vulnerability
Please let us know if you have found a security vulnerability in our software or web services.
We respect responsible disclosure. We would appreciate if a reporter does not disclose information about a vulnerability until a fix is released or within 120 days since the reporting time.
A vulnerability report can be submitted anonymously. But if you expect a reply from us, please provide your contact information below. We recommend you to use encryption for the submitted data and files. The link to our PGP key can be found below.
Privacy Policy | Vulnerability Disclosure Policy | PGP key Download
Frequently asked questions
Will G DATA contact me after I report a vulnerability?
G DATA may contact a reporter for additional information or files if a vulnerability can't be reproduced in-house. However, for anonymous reports that will not be possible.
Reporters of confirmed vulnerabilities will receive a gift of appreciation from G DATA, however no monetary rewards are possible at this point. More information is available in our Vulnerability Disclosure Policy.
Can I submit my report anonymously?
Communication between G DATA and vulnerability reporters is important, however each report can be submitted anonymously, without specifying your contact information.
G DATA will not track any reporter and there will be no legal action for reporting vulnerabilities in our products or services.
Please note that anonymous reports can be only processed to a limited extent due to missing contact options to request additional technical details. In addition, if no contact information is provided, G DATA will not be able to acknowledge received reports and will not be able send gifts of appreciation for confirmed vulnerabilities.
Does my report need to be encrypted?
Encryption is not required, but highly recommended for vulnerability reporting. You can download our PGP key here and encrypt your ZIP archive containing the proof-of-concept and other relevant files.
If you would also like to encrypt your vulnerability report, please put it as a text file into the same ZIP archive and encrypt the archive with our PGP key.
To encrypt your submission you can use any freely-available software that allows PGP encryption, for example OpenPGP.
Can I also report security vulnerabilities via email?
You can also send a vulnerability report via e-mail to the security@gdata.de. Use a burner address if you wish to stay anonymous.
How long does it take for G DATA to respond?
Response times for received vulnerability reports and mitigation solution creation times can be found in our Vulnerability Disclosure Policy.