PSTI Compliance
Information On How to Report Security Issues
We encourage and welcome all reports related to product security or user privacy. We will adhere to established procedures to address these reports and provide timely feedback.
Report Vulnerabilities to QUAD
Responsible Reporting Guidelines
2. Vulnerability reports should be based on the latest released firmware and preferably written in English.
3. Report vulnerabilities through the dedicated communication channel. Although we may receive reports from other channels, we do not always guarantee that the report will be acknowledged.
4. Always adhere to data protection principles and do not violate the privacy and data security of QUAD product users, employees, agents, services, or systems during the vulnerability discovery process.
5. Maintain communication and cooperation during the disclosure process and avoid disclosing information about the vulnerability before the agreed-upon disclosure date.
6. QUAD does not currently operate a vulnerability bounty program.
How We Deal with Vulnerabilities
We will respond to vulnerability reports as soon as possible, usually within 10 business days. Our security team will work with the product team to perform a preliminary analysis and validation of the report to determine the validity, severity, and impact of the vulnerability. We may contact you if we need more information about the reported vulnerability.
Once the vulnerability has been identified, we will develop and implement a remediation plan to provide a solution for all affected customers. Remediation typically takes up to 90 days and in some cases may take longer.
You can keep up to date with our progress and the completion of any remediation activities by visiting our firmware and software downloads section. Release notes will detail updates that relate to security improvements and resolutions.
QUAD will issue an update or security advisory when one or more of the following conditions are met:
The QUAD security team has rated the severity of the vulnerability as CRITICAL. We have completed the vulnerability response process and have identified sufficient mitigation solutions to assist customers in eliminating all security risks.
If the vulnerability has been actively exploited and is likely to increase the security risk to our customers, or if it is likely to raise public concern about the security of QUAD products, we will expedite the release of a security bulletin. This bulletin may or may not include a full firmware patch or emergency fix.
Information on Minimum Security Update Periods
The Support Period for QUAD components is actively maintained, considering security updates, for a minimum of three years from product launch.
Model | Launch Date | Minimum Suport Period * |
ARTERA SOLUS PLAY | 16/01/2020 | 31/12/2026 |
VENA II PLAY | 11/07/2019 | 31/12/2026 |
* Please note: This is a statement of minimum support period obligation. However this date is not indicative of actual support expiry. Please feel free to contact us for further details or queries.
Report Form
Please enter your details and message below.