Informação legal
Security and vulnerabilities
1. Point of contact
Please send reports to support@comparedesk.eu. The same address is given in /.well-known/security.txt. We acknowledge receipt within 48 hours and provide an initial assessment within five working days.
2. Our undertaking to reporters
We will not take legal action against anyone reporting in good faith, provided no third-party data has been exfiltrated and publication is withheld until a remedy is available, at the latest ninety days after our acknowledgement. We will credit you on publication if you wish.
3. How we proceed
Each report is assessed by exploitability, impact on the confidentiality of the documents processed and the spread of the affected versions. Remediation follows without delay and, where possible, separately from functional changes. After release we publish the fixed vulnerability with a description, its severity and the steps to be taken. Security fixes are free of charge for all users, including the free version.
4. Reporting obligations under European law
Article 14 of Regulation (EU) 2024/2847 (Cyber Resilience Act) applies since 11 September 2026. If we become aware of an actively exploited vulnerability or a severe security incident, we submit an early warning within 24 hours and a full notification within 72 hours to the competent national CSIRT and to ENISA; the final report follows within fourteen days of a remedy becoming available. Affected users are informed without delay.
5. Support period
We provide security fixes for each released version for at least five years from its placing on the market. For the versions of series 4.2 currently distributed, the undertaken period ends in December 2031. The expiry of a paid licence does not end that period, nor does that period extend the right to use the paid functions.
6. How CompareDesk is built
The comparison runs entirely on the user's own computer. No documents, file names, paths, checksums or usage data are transmitted. In operation the program opens only the version check and the licence check; both can be switched off and set centrally. An update is installed only after its signature, its source, its checksum and its Authenticode signature have been verified. Foreign files are treated as hostile: limits on unpacking, no execution of macros, no carrying over of foreign macro code into the result file. The working traces of a comparison are removed after the run and also after an abort.