Coordinated Vulnerability Disclosure Policy
WDM Webdesign München GmbH for security-txt.de and security-txt.eu. Version 1.0, as of 10 October 2026, next review by October 2027 at the latest.
We take the security of our tools and servers seriously and thank everyone who reports vulnerabilities to us. This policy describes how to report a vulnerability, what you can expect from us and what we expect from you. It follows section 4.4 of BSI TR-03183-3.
1. Scope
This policy covers the websites security-txt.de and security-txt.eu, the security.txt generator, the security.txt checker, the monitoring service and the servers behind them. It does not cover third-party services we use (such as Cloudflare, Stripe, Postmark, Mittwald); please report flaws there to the respective provider.
2. How to report a vulnerability
- Tools and monitoring (PSIRT): psirt@security-txt.de, key psirt.asc,
CC07 57D0 5B82 4E1C 03F5 F1E3 73E2 57E2 EB6D 57E0 - Website and servers (CSIRT): csirt@security-txt.de, key csirt.asc,
9332 1E57 A9D5 F5BE A65D DB5A DA13 5FC5 5394 F1BC - Web form, anonymous reports possible: https://security-txt.eu/security-contact/
Please send confidential information encrypted and signed by e-mail. We handle reports in English and German. Helpful details are: the affected address or component, a description, steps to reproduce and the possible impact. Please give at least one way to contact you, ideally an e-mail address; we accept e-mail addresses and phone numbers. Status enquiries are always welcome.
3. What we consider a vulnerability
- The vulnerability affects the scope above.
- The information is, as far as possible, not yet publicly known.
- We cannot treat output of automated tools or scans without a comprehensible proof as a report.
We also accept and review reports about vulnerabilities that have already been fixed.
4. Our commitments
- We treat every report confidentially to the extent permitted by law, except for information needed to publish the vulnerability.
- We do not pass on your personal data to third parties without your explicit consent.
- We respond within the deadlines in section 6.
- We will not file a criminal complaint against you as long as you follow this policy. This does not apply where criminal intent is evident.
- We remain available to you throughout the process and do not require a non-disclosure agreement.
- On request we name you after the process is completed, with your name or alias and a link of your choice, in our acknowledgments.
We do not pay rewards (no bug bounty programme).
5. What we expect from you
- You do not exploit the vulnerability beyond the proof and cause no damage.
- You do not attack our systems, for example through social engineering, spam, denial of service or password guessing. Please do not call the checker or the forms in bulk.
- You do not access our customers' data and do not alter systems or data of third parties.
- You do not offer tools to exploit the vulnerability, neither for money nor for free.
Anyone who does not comply will not be named in the acknowledgments. We will still handle the report as well as we can. Everyone involved treats each other with respect; there is no room for discrimination, sexism or insults.
6. Process and deadlines
- Within 5 working days you receive a personal reply to your report or to an addition, not an automatic confirmation.
- Within 10 working days you receive detailed feedback: whether we confirm or reject the vulnerability, specific questions, or a reason why the review takes longer, with further feedback within 10 working days.
- No report is closed by a single person; a second person reviews every decision.
The deadlines do not apply to anonymous reports. We can process anonymous reports only to a limited extent or in some cases not at all, because we cannot ask follow-up questions.
7. Actively exploited vulnerabilities
If a vulnerability in our tools or on our servers is actively exploited, we inform CERT-Bund at the German BSI without delay and coordinate further steps with it.
8. Publication
We publish confirmed vulnerabilities on this website within 90 days. If there is a good reason for a longer fix, we extend the deadline once by a further 90 days in coordination with CERT-Bund. We agree the timing with you.
9. Closing the process
A process is closed when the information turns out to be unfounded, when the vulnerability has been fixed and published, or when the reporting person has not answered questions for at least 30 days and the report therefore cannot be processed further. We inform you of the closure without delay, except for anonymous reports.
10. Data protection
How we process your data when you report is described in our privacy policy.