Privacy policy
This website sets no cookies and loads no embedded third-party services, apart from spam protection on the checker and forms. Everything we process is listed here. This English version is a translation; the German version prevails.
1. Controller
WDM Webdesign München GmbH, Deisenhofener Str. 45, 81539 München, Germany, phone +49 89 856 371 02, e-mail info@security-txt.de, represented by its managing director Marie-Anne Le Corre. We are not legally required to appoint a data protection officer; please send data protection enquiries to the address above.
2. Visiting the website, hosting and Cloudflare
When you visit this website, the web server processes technically necessary data: IP address, date and time, requested page, amount of data transferred, browser type and operating system, previously visited page (referrer). These data are stored in server log files and deleted after 14 days at the latest. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the secure and stable operation of the website and defence against attacks.
The website is hosted in Germany by Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4-6, 32339 Espelkamp. We have a data processing agreement with Mittwald under Art. 28 GDPR.
All requests pass through the content delivery network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare forwards requests to the web server, protects the website against attacks and processes the same technical data, in particular your IP address. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is a secure and fast website. We have a data processing agreement with Cloudflare including the EU standard contractual clauses; Cloudflare is also certified under the EU-US Data Privacy Framework.
3. security.txt generator
The generator builds the file entirely in your browser. To improve the tool and to see which websites it is used for, we log on our own server: the page visit, the first input, the chosen standard (RFC 9116 or BSI TR-03183-3), which explanations were opened, which types of errors were shown, copying or downloading the file and downloading the policy draft including its language, whether a mobile or desktop device was used, whether you use the German or English site and which page you came from (our own page or the host name of an external website). When you copy or download the file we also store the domain you entered (for example company.com), the selected languages, how many months the file is valid, and for each field only whether it was filled in by you, derived automatically or left empty. For the policy draft we store only whether name and phone were filled in, not the details themselves. E-mail addresses, web addresses, company name and phone number are not transmitted. Your browser assigns a random identifier that is kept only while the browser tab is open (sessionStorage); we store no IP address and set no cookies. A domain may relate to a person, for example if it contains a name. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is improving the tool and understanding which websites it is used for.
4. security.txt checker
For a check, our server fetches the file at the domain you entered and the addresses and keys linked in it. If a signature cannot be verified with those keys, we look up the key on the public key server keys.openpgp.org; only the key identifier is transmitted, nothing about you. We store the checked domain, the time, the language of the site, where the file was found, the retrieval status, the result of the signature check, the days until expiry and the types of findings (for example "expiry date missing"), plus the page from which the check was started and a random identifier of the browser tab (sessionStorage). We do not store the content of the file or your IP address.
To protect against abuse, spam and automated requests, we also log every request to the checker and to the monitoring forms, including rejected ones: time, result and reason for rejection if any, the domain entered, your browser identifier (user agent), the referring page, the country Cloudflare derives from the IP address and, instead of the IP address, a shortened hash that changes daily and cannot be reversed. We delete this access log after 30 days. We also use this hash to count how often each IP address checks; the counters are deleted after a short time. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is operating and improving the tool and preventing abuse.
5. Spam protection with Cloudflare Turnstile
On the checker, the monitoring order form, the form for requesting a management link and the report form we use Cloudflare Turnstile by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Turnstile is loaded only on these pages, checks in the browser whether the input comes from a human and processes in particular your IP address and technical characteristics of browser and device; a task to click appears only in case of doubt. According to Cloudflare, Turnstile sets no cookies. A transfer to the USA is possible; Cloudflare is certified under the EU-US Data Privacy Framework and we have a data processing agreement with Cloudflare. More information: Cloudflare privacy policy. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protection against spam and abuse.
6. Monitoring
When you order monitoring, we process your company name, your e-mail address, the domains you enter, the chosen standard and the language of the site. As long as online payment is not yet enabled, these details reach us as a request by e-mail. After that we store the order on our server and forward you to Stripe for payment.
Payment is handled by Stripe Payments Europe, Limited, One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland. On Stripe's pages you enter your billing address, your VAT ID if applicable and your payment details; we do not receive these data, except for the customer and subscription identifiers and the payment status. Stripe also processes payment data for its own purposes (such as fraud prevention and legal obligations) as an independent controller; see the Stripe privacy policy. You manage invoices, payment method and cancellation in Stripe's customer portal.
For monitoring we fetch the security.txt of your domains once a day and check it as the checker does. For each domain we store the latest check status (time, result, types of findings, expiry dates of the file and the keys, reminders sent) and keep a check log. We send results, reminders and the quarterly check report by e-mail to the address you gave. For sending we use Postmark by ActiveCampaign, LLC, 1 North Dearborn Street, Chicago, IL 60602, USA; we have a data processing agreement with ActiveCampaign including the EU standard contractual clauses, ActiveCampaign is also certified under the EU-US Data Privacy Framework, and Postmark keeps message content for at most 45 days.
The legal basis is Art. 6(1)(b) GDPR (contract). We keep subscription data for the duration of the contract. After it ends we delete check status and check logs after 90 days; we and Stripe keep invoices and accounting records for the statutory retention periods of up to ten years.
7. Reporting vulnerabilities
You can report security issues to us via the report form and the addresses psirt@ and csirt@security-txt.de. We process the content of your report and, only if you provide them, your name or alias and your e-mail address or phone number. We send form submissions by e-mail via Postmark to our mailbox at Mittwald; on the server we store only when a report arrived, which area it concerns and whether it was anonymous, not its content. The purpose is to review and fix the reported vulnerability and to reply to you; the legal basis is Art. 6(1)(f) GDPR (legitimate interest in the security of our services). We do not pass on your contact details to third parties without your explicit consent. We publish your name or alias in the acknowledgments only if you wish. We delete the report once the process is completed and no retention obligation applies. Anonymous reports are possible.
8. Audience measurement with Plausible
To understand which pages are read and where visitors come from, we use Plausible Analytics by Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. Plausible sets no cookies and stores nothing on your device. It records the page visited, the referring website, campaign parameters in the address if any, browser, operating system, device class, the country and region derived from the IP address, how far and how long a page was read, and clicks on external links, downloads and form submissions (without their content). Measurement runs through our own server: your browser sends the data to our domain and our server passes them on to Plausible. Your IP address and browser identifier (user agent) are not stored; Plausible combines them with a daily changing random value into a hash to count the visits of one day and deletes the random value after 24 hours. Recognition across several days or websites is therefore not possible. Plausible stores the data on servers in the EU (Germany); we have a data processing agreement with Plausible. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is improving our offering. More information: Plausible data policy.
9. No cookies, no embedded services
This website sets no cookies. Fonts are loaded from our own server. No maps, videos, social media buttons or third-party chat services are embedded. The only exception is Cloudflare Turnstile (section 5). Stripe's information applies on Stripe's pages (payment, customer portal).
10. Recipients
Your data are disclosed only to the service providers named in this policy (Mittwald, Cloudflare, Plausible, ActiveCampaign/Postmark) and to Stripe for payment. If a vulnerability in our services is actively exploited, the content of a report may go, without your contact details, to CERT-Bund at the German BSI (section 7). Transfers to third countries take place only by Cloudflare and by sending via Postmark to the USA, based on the EU-US Data Privacy Framework and the EU standard contractual clauses.
11. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) GDPR (Art. 21). Please contact the address in section 1. You also have the right to lodge a complaint with a data protection supervisory authority; the authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht), Promenade 18, 91522 Ansbach, Germany.
12. Changes
We update this policy when the website or the legal situation changes. As of October 2026.