Security — How to Report a Vulnerability in VidVertex
SECURITY·REPORTING A VULNERABILITY

Security

VidVertex runs on your own machine and holds the keys to your posting accounts, so a security problem in it is a security problem for your channels. If you find one, we want to hear about it — here is how, and what happens next.

Reporting a vulnerability

Write to support@vidvertex.com with "Security" in the subject line. An alias address is fine; you can stay anonymous.

Useful in a report:

  • which part it affects — the VidVertex app, the free VidVertex Downloader, or vidvertex.com
  • the app version (the hub toolbar shows it) and your Windows version
  • what someone could do with it, and what they would need first — a file you open, access to your network, a local account
  • steps to reproduce it, a proof of concept, or a log excerpt
usually 3 working daysReceipt confirmed
usually 10 working daysAssessment
24 hoursEarly warning we file
72 hoursFull notification

What happens then: we usually confirm we got it within 3 working days and come back with an assessment within 10 working days, and we keep you posted until it is fixed. Fixes ship as a normal in-app update. We do not run a paid bug bounty, but we credit reporters by name if they want that.

Our promise to reporters

If you report in good faith, we will not take legal action against you over the research, and we will not ask anyone else to. In return we ask you to:

  • give us reasonable time to ship a fix before you publish
  • stay on your own machine, your own data and your own accounts
  • leave other people's data alone, and skip denial-of-service tests, spam and anything physical
  • not make the report conditional on a payment
NOTE

VidVertex is a desktop app. Your footage, your API keys and your rendered files are stored on your machine; connected services receive the data needed for the features you use. The interesting surface includes the update path, the local engine API and the files the app reads. Findings there are especially welcome.

Our reporting duties

From 11 September 2026 the EU Cyber Resilience Act (Regulation (EU) 2024/2847) obliges us to report some events ourselves. When a vulnerability in one of our products is actively exploited, or a severe security incident affects the security of a product, we file with the ENISA Single Reporting Platform, which passes the report on to our national CSIRT — in Germany the BSI/CERT-Bund:

  1. Early warning within 24 hours of becoming aware of it.
  2. A full notification within 72 hours — what we know so far, the state of the fix, and what users can do in the meantime.
  3. A final report: for an actively exploited vulnerability, no later than 14 days after a corrective or mitigating measure is available; for a severe incident, within one month of the full notification. It describes the cause, impact and measures taken.

These timelines follow the European Commission's reporting guidance.

Where you have to act, we say so in the release notes and in the in-app update dialog. A newly published CVE in a component we bundle is not by itself a reportable event — active exploitation or a severe incident is.

Machine-readable contact

The same contact details are published at https://vidvertex.com/.well-known/security.txt in the format of RFC 9116.