SECURITYSQUAD

Report a vulnerability

Anyone who finds a weakness in our systems should know who to tell – and what happens next.

Testing other people's systems is our job, so we know how frustrating it is when a report goes nowhere. Hence this page: it is the policy our security.txt points to under RFC 9116, and it covers reports about our own systems.

Where to report

Send your report to support@securitysquad.de

Anything that shortens the path to reproduction helps:

  • the domain or URL affected and when you observed it
  • a brief description of what is possible and why that is a problem
  • the steps to reproduce, ideally with requests and responses in plain text
  • how we can reach you, and whether you would like to be credited by name

German and English are equally welcome.

Scope

This policy covers systems we operate ourselves:

  • securitysquad.de and the subdomains we run
  • our publicly reachable services, such as the Security Score Check

It does not cover systems that are not ours to change:

  • our customers' systems – please report findings there to the operator directly
  • third-party services we merely integrate, such as Microsoft Bookings or our DNS provider
  • reports that consist solely of a scanner result with no demonstrable impact

What we ask of you

In Germany there is a criminal-law line between a good-faith report and unauthorised access (sections 202a ff. of the Criminal Code). To keep you on the right side of it:

  • Limit yourself to what is needed for proof. No widening the scope, no pulling in further tooling.
  • No attacks on availability, no load testing, no large-scale guessing.
  • If you come across personal data: stop immediately, copy nothing, store nothing, and tell us in the report.
  • Give us time to fix it before you publish. Do get back to us if it takes too long – we do not expect open-ended silence.

What we commit to

  • We confirm receipt of your report and will not leave you without an answer.
  • We keep you posted on the state of the fix and tell you when it is done.
  • Anyone who follows the rules above and reports in good faith has no legal action to fear from us.

No bug bounty

We pay no bounties – we would rather say so plainly than let you find out after the work. If you would like, we will credit you by name once the finding is fixed.

This page is the policy referenced by our security.txt under RFC 9116, available at /.well-known/security.txt.