Responsible disclosure
Reporting vulnerabilities responsibly
This English version is provided for convenience. In case of discrepancies, the German version prevails.
How to report
Send a comprehensible description, the affected URL or function, safe steps to reproduce and the possible impact to office@pock.biz. Please mark the message as a confidential security report.
Safe testing
- Use only your own accounts and data; do not access, modify or publish other users' data.
- No social engineering, phishing, DDoS, spam or physical attacks.
- No persistence, malware or excessive automation; stop as soon as personal data or critical access becomes visible.
- No publication before we have had a reasonable opportunity to investigate and remediate.
How we handle reports
We acknowledge qualified reports, prioritise them by risk, keep the reporter informed to a reasonable extent, and take no legal action over good-faith, proportionate research within these rules. This does not create any claim to a bug bounty or payment.
Not treated as a vulnerability
Version banners without demonstrated impact, automated scanner reports without verification, missing general security headers without a concrete risk, and social engineering scenarios are regularly not considered qualified reports.
MASPro