// Security

Vulnerability Disclosure Policy

The security of our systems and of our clients' data is a top priority for Reg-Bytes GmbH. Despite all care, vulnerabilities can occur. If you discover a vulnerability, please disclose it to us responsibly so we can fix it quickly.

Reporting process

Send your findings by email to security@reg-bytes.de. We will confirm receipt and keep you informed about the progress.

Please use this address for security matters only. General enquiries, support or contractual topics belong to info@reg-bytes.de.

Provide details

So that we can assess your report quickly, please provide as much detail as possible:

  • A detailed summary of the vulnerability
  • The affected attack surface (e.g. URL and parameters)
  • The potential vulnerability or vulnerability class
  • Tools used and your approach
  • A proof of concept demonstrating exploitability
  • Your severity assessment: low, medium, high or critical
  • Any plans for public disclosure

We prefer a plain-text email per vulnerability so each report can be tracked separately.

Vulnerabilities in open-source projects

If the vulnerability affects an open-source component, please also report it directly to the affected project so the community benefits promptly. We are happy to coordinate with the maintainers where needed.

Rules

Please observe the following principles during your research:

  • Do not violate the privacy of third parties
  • Do not degrade or disrupt our services
  • No unauthorised access to data, and no modification or deletion of data
  • Do not share information with third parties before the vulnerability is fixed

Next steps

  • Receipt confirmation and initial assessment within 24 hours (business days)
  • After the initial assessment, within 72 hours: status of your report and planned measures
  • After validation and remediation: affected customers are notified and — where appropriate — a security advisory is published

Policy updates

Reg-Bytes GmbH may update this policy at any time. Material changes are communicated via this website.

Thank you

We thank everyone who reports findings and helps us protect our systems and our clients' data.

Would you rather report a concrete security incident? Report a security incident