Report a vulnerability

How to report a security issue to us, what we commit to and what is off limits when testing.

How to report

Write to hello@patchletter.com, in German or English. Please send only a short description without exploitable details at first. We then agree a confidential channel with you for the rest.

It helps to include:

  • the affected address and the time of your observation,
  • the steps needed to reproduce the behaviour,
  • your assessment of the impact,
  • whether and how you would like to be credited.

What we commit to

  • We reply within 72 hours.
  • We keep you informed about assessment and remediation.
  • After the fix we publish together with you, if you wish.
  • We credit you as the finder, provided you agree.

There is no bounty programme.

What is in scope

In scopeOut of scope
the website at privymail.eu and www.privymail.euthird-party systems, such as those of hosting, DNS or certificate providers
its delivery: TLS, security headers, redirectsdenial-of-service attacks and automated mass requests
the published transparency files and their signaturedeceiving people and physical access
reports without a demonstrable impact, such as bare version numbers

Rules for testing

  • Test only as far as needed to demonstrate the issue.
  • Do not access other people's data, and do not change or delete anything.
  • Do not impair availability.
  • Give us time to fix the issue before you publish details.

Anyone who follows these rules is, in our view, acting in good faith. This is not a legally reviewed statement waiving legal action (safe harbour).

The machine-readable version is at /.well-known/security.txt. The architecture is described under Security.