MASProLegal

Responsible disclosure

Reporting vulnerabilities responsibly

Last updated: 21 August 2026

This English version is provided for convenience. In case of discrepancies, the German version prevails.

How to report

Send a comprehensible description, the affected URL or function, safe steps to reproduce and the possible impact to office@pock.biz. Please mark the message as a confidential security report.

Safe testing

How we handle reports

We acknowledge qualified reports, prioritise them by risk, keep the reporter informed to a reasonable extent, and take no legal action over good-faith, proportionate research within these rules. This does not create any claim to a bug bounty or payment.

Not treated as a vulnerability

Version banners without demonstrated impact, automated scanner reports without verification, missing general security headers without a concrete risk, and social engineering scenarios are regularly not considered qualified reports.