Responsible Disclosure
Security is our daily business. If you discover a vulnerability in our systems, we want to hear about it and fix it together with you. This policy explains how to report an issue and what you can expect from us.
How to report a vulnerability
Send your report to security@cybervize.de.
To help us triage it quickly, please include:
- A description of the vulnerability and its potential impact.
- The affected URL, domain, or component.
- Clear steps to reproduce, ideally with screenshots or a proof of concept.
- Your contact details for follow-up questions.
Reports in English or German are equally welcome.
Encrypted reports
For confidential reports, you can encrypt your message with our PGP key. Please verify the fingerprint before using the key.
Fingerprint: E526 B224 648E 231F 33CA C548 0309 F0D1 7AAE 7C78
Our commitments
- We acknowledge receipt of your report, as a rule within five business days.
- We assess the report by severity and keep you informed about its status.
- On request, we credit you as the finder once the issue is resolved.
- We do not currently run a paid bug bounty program.
Safe harbor
As long as you follow this policy and act in good faith, we consider your testing authorized. In that case we will not pursue legal action against you and will work with you to understand and resolve the issue.
Scope
This policy covers the systems reachable under cybervize.de and its subdomains. If you find something at one of our service providers, please report it to us anyway and we will forward it.
Please avoid
For your research to count as good faith, please respect the following limits:
- No denial-of-service attacks and no testing that degrades our live service.
- No social engineering of staff, customers, or partners, and no physical attacks.
- Do not access third-party data, do not modify or delete data, and stop once you have demonstrated the vulnerability.
- Disclose details only after we have resolved the issue, and in coordination with us.
Last updated: May 2026
