Security

Vulnerability Disclosure Policy  


HQLAx is committed to security and therefore welcomes security reports. All security issues found in relation to HQLAx should be reported by email to security@hqla-x.com. If possible, please encrypt your email; our PGP key is at the bottom of this page. HQLAx's Security Team will acknowledge your email and initiate an investigation as soon as is practically possible. Advisory-class issues may require coordinated disclosure with our customers and partners before being made publicly available.

As with any security related activity, security reporters are expected to comply with all applicable laws and regulations in the course of their research activities, and in a manner that protects the property and privacy of HQLAx’s customers and partners. When submitting a security report, we are committed to working in good faith with the security community. HQLAx requires that vulnerability submissions are conducted following a responsible disclosure model. Please do not include any identifiable information (name, contact information, or similar information) in your communications.

Disclosure Process


Send email to: security@hqla-x.com

Please include the following information:

• a description of the vulnerability and the environment in which it was discovered;
• the name, version and configuration of the product or service that is affected;
• detailed steps that can reproduce the issue.

Please limit as much as possible large attachments or executable files as the email might be flagged as spam.

Download our PGP Key here.

PGP fingerprint: B8F0 EE14 9C57 1299 86CB  D812 62E8 206F 0906 AEF0