Report a vulnerability
Found a security issue in this website, the generator, the checker or the monitoring service? Thank you for letting us know. Here are all the ways to reach us, encrypted or anonymously.
How we handle reports is described in our coordinated vulnerability disclosure policy. This information is valid until 9 October 2027 and will be renewed before then.
Reporting channels
Tools and monitoring (PSIRT)
Flaws in the generator, checker and monitoring.
OpenPGP key: psirt.asc
Fingerprint:CC07 57D0 5B82 4E1C 03F5 F1E3 73E2 57E2 EB6D 57E0
Website and servers (CSIRT)
Flaws in this website, its forms and servers.
OpenPGP key: csirt.asc
Fingerprint:9332 1E57 A9D5 F5BE A65D DB5A DA13 5FC5 5394 F1BC
Please send confidential information encrypted and signed. Not sure where it belongs? Write to psirt@ and we will forward it internally. We reply in English and German.
Our security.txt is signed with a dedicated key: security-txt-signatur.asc, fingerprint 8556 11C5 DBB1 2113 239F FC3C 44F4 1C5B 55FD 42DC.
Report form
You may report without name or contact details. Without contact details, however, we cannot ask follow-up questions, so we can process anonymous reports only to a limited extent or in some cases not at all, especially complex ones.
What happens next
- Within 5 working days a person replies to you, not an automatic confirmation.
- Within 10 working days you receive detailed feedback: confirmation or rejection, questions, or a reason why it takes longer.
- We do not require an NDA and will not file a criminal complaint as long as you follow our policy.
- We publish confirmed vulnerabilities within 90 days and agree the timing with you.
Status enquiries are always welcome.
Acknowledgments
Here we thank everyone who reported a valid vulnerability and wishes to be named. There are no entries yet.