# Report a vulnerability

> How to report a security issue to us, what we commit to and what is off limits when testing.

## How to report

Write to [hello@patchletter.com](mailto:hello@patchletter.com), in German or English. Please send only a short description without exploitable details at first. We then agree a confidential channel with you for the rest.

It helps to include:

- the affected address and the time of your observation,
- the steps needed to reproduce the behaviour,
- your assessment of the impact,
- whether and how you would like to be credited.

## What we commit to

- We reply within 72 hours.
- We keep you informed about assessment and remediation.
- After the fix we publish together with you, if you wish.
- We credit you as the finder, provided you agree.

There is no bounty programme.

## What is in scope

| In scope | Out of scope |
|---|---|
| the website at privymail.eu and www.privymail.eu | third-party systems, such as those of hosting, DNS or certificate providers |
| its delivery: TLS, security headers, redirects | denial-of-service attacks and automated mass requests |
| the published transparency files and their signature | deceiving people and physical access |
| | reports without a demonstrable impact, such as bare version numbers |

## Rules for testing

- Test only as far as needed to demonstrate the issue.
- Do not access other people's data, and do not change or delete anything.
- Do not impair availability.
- Give us time to fix the issue before you publish details.

Anyone who follows these rules is, in our view, acting in good faith. This is not a legally reviewed statement waiving legal action (safe harbour).

The machine-readable version is at `/.well-known/security.txt`. The architecture is described under [Security](https://privymail.eu/en/security.md).

---

- This page as HTML: https://privymail.eu/en/disclosure/
- Deutsche Fassung: https://privymail.eu/disclosure.md
