Report a vulnerability
Have you found a security vulnerability in one of our products? Write to security@querdenkerengineering.de. The mailbox is read by the management. We acknowledge receipt within three working days.
The same details are available in machine-readable form at /.well-known/security.txt.
What this covers
The products we offer under our own name, above all qdCloud and qdCoreX. Reports about our other products and about this website reach us the same way.
If your report concerns a device we developed on behalf of a manufacturer, we pass it on to the manufacturer and tell you that we have done so. The manufacturer places the device on the market and decides on the fix and on publication.
What we need to assess it
- product and version; for qdCoreX, the version of the image
- what you observed and how it can be reproduced
- the impact you expect
- how we can reach you and whether we may name you in the security advisory
Please do not access third-party data, do not change anything and do not disrupt operation.
What happens next
We assess the report against the affected version and tell you whether we can confirm it. If it is confirmed, we build a fix and deliver it through the product's update path.
We agree the time of publication with you. Please give us time for the fix before you publish details. As a guideline, we ask for 90 days from your report.
We do not run a bounty programme. If you wish, we name you in the security advisory.
Security advisories
We have not published a security advisory so far. As of September 2026.
