Zum Hauptinhalt springen

Product Security

ONE WARE GmbH welcomes responsible reports that help protect ONE WARE products and customers.

Report a Security Vulnerability

Do not disclose a suspected vulnerability through public issues, discussions, pull requests, Discord, or general support channels.

Report it privately by email:

Include, where possible:

  • The affected product, version, and distribution channel.
  • A description of the vulnerability and its potential impact.
  • Reproduction instructions or a proof of concept.
  • Relevant logs or screenshots with credentials and personal data removed.
  • Any suggested mitigation.

Request the current PGP key by email before sending sensitive details that require encryption.

Response Targets

StageTarget
Acknowledge receiptWithin 3 business days
Initial assessment and severity triageWithin 10 business days
Status updates during remediationAt least every 14 days
Fix or documented mitigationAs soon as practicable, prioritised by severity

ONE WARE follows coordinated vulnerability disclosure. Reporters are asked to allow a reasonable opportunity to investigate and remediate before public disclosure. Reporters who request acknowledgement will be credited where appropriate.

The repository-specific policy for the open-source desktop application is also available in the ONE WARE Studio repository.

Testing Rules

The following activities are out of scope and prohibited without prior written authorisation:

  • Denial-of-service or volumetric testing against production systems.
  • Accessing, changing, downloading, or deleting another user's data.
  • Social engineering, phishing, or physical attacks.
  • Automated scanning that degrades service or produces no demonstrated security impact.
  • Public disclosure before ONE WARE has had a reasonable opportunity to respond.

Stop testing and contact ONE WARE immediately if personal data, credentials, customer data, or production secrets are encountered.

Security Updates and Support

Security updates are provided without a separate charge during the applicable support period:

ProductSecurity support commitment
ONE WARE StudioAt least 5 years from each release
OneWare.AI extensionAt least 5 years from each release
OneWare Self-Hosted WorkerAt least 5 years from each release
Hosted OneWare Cloud and managed server componentsMaintained and security-patched while the service is offered

Users should install security updates promptly and follow the secure configuration or deployment guidance supplied with the product. Product-specific supported versions and end-of-support information will be published with the relevant release or product documentation.

Security Advisories

Confirmed issues that require customer action are communicated through the relevant product's release notes or security advisory, in-product or service notifications where available, and direct customer communication where necessary. Do not rely on this page alone for urgent product notifications.

Detailed security assessments, vulnerability records, and software bills of materials may contain sensitive information and are provided to competent authorities or customers where legally or contractually required; they are not published on this page.