Security is our top priority

The security of our products and the protection of our customers are our top priorities.

If you have discovered a vulnerability in our website, our services, our hardware, or our software, we ask that you report it to us responsibly. To this end, we offer security researchers, customers, and third parties a central point of contact to report potential security vulnerabilities confidentially.

Your report to us

Please send your report to:

Email: security@head-acoustics.com

To transmit confidential data, please use our PGP key(s), which is available at 
https://www.head-acoustics.com/security-mail-pgp-key.txt.

Alternatively, you can use the following form:

Our Data Privacy Policy applies.

* Mandatory

What your report should include

To help us review and process your report as quickly as possible, please provide the following information:

  • Affected product/software, including the exact version number or hardware revision.
  • A detailed description of the vulnerability (e.g., type of vulnerability, impact).
  • Step-by-step instructions or a proof-of-concept (PoC) for reproducing the vulnerability.
  • Your contact information in case we have any follow-up questions (anonymous reports are possible upon request).

Our review process

Upon receipt of your report, we follow this procedure:

  • Acknowledgment of receipt: We typically confirm receipt of your report within 48 hours.
  • Resolution & Transparency: We develop a fix (patch/update) and keep you informed of our progress. After the fix is released, we coordinate the disclosure (CVD) as necessary.

Safe harbor / Legal shield

If you act in good faith during your research and reporting and adhere to the following rules, we will not take legal action against you:

  • No data corruption: Avoid actions that result in downtime, data loss, or violations of others' privacy.
  • Confidentiality: Give us a reasonable amount of time to fix the vulnerability before you make information about it public.
  • No abuse: Do not exploit the vulnerability for your own purposes (e.g., data exfiltration or extortion).