security-txt.eu

Coordinated Vulnerability Disclosure Policy

WDM Webdesign München GmbH for security-txt.de and security-txt.eu. Version 1.0, as of 10 October 2026, next review by October 2027 at the latest.

We take the security of our tools and servers seriously and thank everyone who reports vulnerabilities to us. This policy describes how to report a vulnerability, what you can expect from us and what we expect from you. It follows section 4.4 of BSI TR-03183-3.

1. Scope

This policy covers the websites security-txt.de and security-txt.eu, the security.txt generator, the security.txt checker, the monitoring service and the servers behind them. It does not cover third-party services we use (such as Cloudflare, Stripe, Postmark, Mittwald); please report flaws there to the respective provider.

2. How to report a vulnerability

Please send confidential information encrypted and signed by e-mail. We handle reports in English and German. Helpful details are: the affected address or component, a description, steps to reproduce and the possible impact. Please give at least one way to contact you, ideally an e-mail address; we accept e-mail addresses and phone numbers. Status enquiries are always welcome.

3. What we consider a vulnerability

We also accept and review reports about vulnerabilities that have already been fixed.

4. Our commitments

We do not pay rewards (no bug bounty programme).

5. What we expect from you

Anyone who does not comply will not be named in the acknowledgments. We will still handle the report as well as we can. Everyone involved treats each other with respect; there is no room for discrimination, sexism or insults.

6. Process and deadlines

The deadlines do not apply to anonymous reports. We can process anonymous reports only to a limited extent or in some cases not at all, because we cannot ask follow-up questions.

7. Actively exploited vulnerabilities

If a vulnerability in our tools or on our servers is actively exploited, we inform CERT-Bund at the German BSI without delay and coordinate further steps with it.

8. Publication

We publish confirmed vulnerabilities on this website within 90 days. If there is a good reason for a longer fix, we extend the deadline once by a further 90 days in coordination with CERT-Bund. We agree the timing with you.

9. Closing the process

A process is closed when the information turns out to be unfounded, when the vulnerability has been fixed and published, or when the reporting person has not answered questions for at least 30 days and the report therefore cannot be processed further. We inform you of the closure without delay, except for anonymous reports.

10. Data protection

How we process your data when you report is described in our privacy policy.