Reporting Vulnerabilities & Security Incidents
Background & Purpose
This policy describes how soft Xpansion facilitates the receipt of external reports concerning suspected or actual vulnerabilities and security incidents in our products with digital elements. It thereby serves to fulfil our related obligations under the Cyber Resilience Act.
We take the security of our products very seriously. Since we cannot simulate and account for every possible real-world usage scenario before releasing a product, we take your reports of possible vulnerabilities and incidents affecting the security of our products very seriously, review them promptly, and take the necessary measures to protect our customers and customer data where required.
If you believe you have found a vulnerability in one of our software solutions, please send us the relevant information. Please submit your report via the reporting channel specified on this page, and observe the notes on which products and product versions you can report to us, what your report should contain so that we can identify and fix the vulnerability, and any other guidelines that apply to reporting. Should a vulnerability be confirmed, we will try to fix it as quickly as possible. This may require us to contact you with follow-up questions.
Scope
The information on this page applies to the current versions of the PDF Xpansion SDK as well as the Perfect PDF product family.
Contact Information for Simple & Targeted Reporting
To report a suspected or actual vulnerability or security incident, please use exclusively the email address security@soft-xpansion.com. This reporting channel can be used directly, without setting up a soft Xpansion account. Please write your report in German or English.
For support inquiries that do not concern a suspected or actual vulnerability/security incident, please always use the following channels instead: for the PDF Xpansion SDK, the online ticket system in your account, and for Perfect PDF, the options shown on the support page.
Information Your Report Should Contain to Help Us Identify the Issue
Please include the following information with your report, as otherwise we may not be able to process it at all, or only to a very limited extent:
- Affected product, including version and build number- Operating system used, including version number
- The most precise description possible of the vulnerability or incident and its possible impact from your point of view
- The steps required to reproduce the issue, including, if applicable, files that exploit or contain the security incident or vulnerability
- Please avoid disclosing confidential information (e.g. names, contact details, account data) in any documents, videos, or screenshots you attach for illustration
- Any indication that the vulnerability has already been actively exploited (if known to you)
- Your valid contact details for follow-up questions and further communication with you, i.e. at least a valid email address — not a "disposable" email address that can only be used once. In the case of an anonymous report with no possibility of follow-up questions, reproducing and fixing the vulnerability may take longer, or may even be impossible.
You can find our privacy policy here.


