Responsible disclosure

    We do our best to keep our systems secure, but nobody is perfect. If you find a weak spot, please tell us. Then we can fix it before someone else misuses it.

    How to report it

    Report it through our contact form: the topic IT security is then already chosen. Describe what you found and how we can verify it. Our security.txt points to these arrangements.

    What we ask of you

    • Do not use the vulnerability further than needed to demonstrate it.
    • Do not view, change or delete other people's data.
    • Do not use attacks that disrupt the service, social engineering or physical access.
    • Do not share the vulnerability with others until it is fixed.

    What you can expect from us

    • We confirm your report, normally within one working day.
    • We keep you informed about the fix.
    • If you follow these rules, we will not report you to the police.
    • We thank you personally. If you like, we mention your name once the vulnerability is fixed.