Product Security
ONE WARE GmbH welcomes responsible reports that help protect ONE WARE products and customers.
Report a Security Vulnerability
Do not disclose a suspected vulnerability through public issues, discussions, pull requests, Discord, or general support channels.
Report it privately by email:
- Email: security@one-ware.com
- Subject:
Security
Include, where possible:
- The affected product, version, and distribution channel.
- A description of the vulnerability and its potential impact.
- Reproduction instructions or a proof of concept.
- Relevant logs or screenshots with credentials and personal data removed.
- Any suggested mitigation.
Request the current PGP key by email before sending sensitive details that require encryption.
Response Targets
| Stage | Target |
|---|---|
| Acknowledge receipt | Within 3 business days |
| Initial assessment and severity triage | Within 10 business days |
| Status updates during remediation | At least every 14 days |
| Fix or documented mitigation | As soon as practicable, prioritised by severity |
ONE WARE follows coordinated vulnerability disclosure. Reporters are asked to allow a reasonable opportunity to investigate and remediate before public disclosure. Reporters who request acknowledgement will be credited where appropriate.
The repository-specific policy for the open-source desktop application is also available in the ONE WARE Studio repository.
Testing Rules
The following activities are out of scope and prohibited without prior written authorisation:
- Denial-of-service or volumetric testing against production systems.
- Accessing, changing, downloading, or deleting another user's data.
- Social engineering, phishing, or physical attacks.
- Automated scanning that degrades service or produces no demonstrated security impact.
- Public disclosure before ONE WARE has had a reasonable opportunity to respond.
Stop testing and contact ONE WARE immediately if personal data, credentials, customer data, or production secrets are encountered.
Security Updates and Support
Security updates are provided without a separate charge during the applicable support period:
| Product | Security support commitment |
|---|---|
| ONE WARE Studio | At least 5 years from each release |
| OneWare.AI extension | At least 5 years from each release |
| OneWare Self-Hosted Worker | At least 5 years from each release |
| Hosted OneWare Cloud and managed server components | Maintained and security-patched while the service is offered |
Users should install security updates promptly and follow the secure configuration or deployment guidance supplied with the product. Product-specific supported versions and end-of-support information will be published with the relevant release or product documentation.
Security Advisories
Confirmed issues that require customer action are communicated through the relevant product's release notes or security advisory, in-product or service notifications where available, and direct customer communication where necessary. Do not rely on this page alone for urgent product notifications.
Detailed security assessments, vulnerability records, and software bills of materials may contain sensitive information and are provided to competent authorities or customers where legally or contractually required; they are not published on this page.