Security
Thank you for helping us keep our systems secure. If you discover a security vulnerability in our services, we ask that you report it to us responsibly.
Contact
Please report security vulnerabilities via email to: [email protected]
For encrypted communication, you can use our PGP key.
Rules of Engagement
We ask that you follow these rules:
- Do not perform attacks that disrupt our services (e.g. DDoS, spam)
- Do not access, modify, or delete other users' data
- No social engineering against our employees or customers
- Do not disclose the vulnerability before we have fixed it
- Give us reasonable time (at least 90 days) to fix the vulnerability
Safe Harbor
If you follow the rules above, we commit to:
- Not taking legal action against you
- Not filing criminal charges for your security research
- Working with you in good faith to understand and fix the vulnerability
Privacy
When you report a security vulnerability to us, we process your email address and name solely for the purpose of communicating about the reported vulnerability. Your data will not be shared with third parties and will be deleted after the vulnerability has been resolved, unless we are legally required to retain it. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of our systems).
Scope
This policy applies to all services under the domain kunstform.org.
Legal Notice
Information pursuant to § 5 TMG can be found in our Legal Notice.