Security

Found a vulnerability? Thank you for reporting it.

As a cybersecurity company we take reports about vulnerabilities in our websites and services seriously. Please report them to us confidentially.

Contact

Send your report to contact@feldmanncyber.com with the subject “Security report”. A machine-readable version of this information is available at /.well-known/security.txt.

Scope

  • feldmanncyber.com and de.feldmanncyber.com
  • app.feldmanncyber.com (FeldmannCyber App)
  • other feldmanncyber.com subdomains operated by us

What your report should include

  • affected URL, component or service
  • type of vulnerability and potential impact
  • steps to reproduce, with a proof of concept if possible
  • when you discovered it
  • how we can reach you for questions (optional — anonymous reports are welcome)

What you can expect

  • We usually confirm receipt within three working days.
  • We investigate, keep you informed and fix confirmed vulnerabilities as quickly as their severity requires.
  • If you wish, we credit you as the finder after the fix.

Rules for responsible testing

  • Access only as much data as needed to demonstrate the issue, and delete it afterwards.
  • No denial-of-service attacks, spam, social engineering or physical attacks.
  • No modification or destruction of data; do not affect other users.
  • Give us reasonable time to fix the issue before disclosing it publicly.

If you follow these rules and act in good faith, we do not intend to take legal action against you.

Rewards

We do not currently run a bug bounty program and do not pay rewards. You have our thanks all the same.