Reporting security vulnerabilities
This is a translation provided for convenience. The German version at https://www.about-quality.de/security/ is the legally binding text.
We welcome every report of a vulnerability. Anyone who alerts us to a problem does us a favour – and our clients too.
Among other things, we advise companies on information security in accordance with ISO/IEC 27001. It would hardly do for us of all people to fend off such reports.
What we promise you
If you search for a vulnerability in good faith and report it to us, we will not file a criminal complaint and will not initiate civil proceedings. That is the norm, not the exception.
This promise applies as long as you keep to the points in the next section.
Two limitations that we should state openly. First: we can only speak for ourselves. If a finding concerns the systems of our hosting provider or of a client, their own rules apply there. Second: a promise from us does not override any law. It is no substitute for legal advice.
What we ask of you
- Go only as far as is necessary to demonstrate the vulnerability
- Do not read, copy, modify or delete other people's data
- Do not disrupt operations – no denial-of-service attacks, no mass mailings
- Refrain from social engineering against our people and from anything requiring physical access
- Treat the finding as confidential until it has been fixed
- Give us a reasonable period of time before you talk about it
How to reach us
E-mail to all@bout-quality.de. Please include:
- the address or function affected
- a short description of how the problem can be reproduced
- an assessment of what someone could do with it
In German or English, either is fine. If you would like to write in encrypted form, just let us know – we will then arrange the route with you.
These details are also available in machine-readable form in the security.txt in accordance with RFC 9116 – identical in wording at rr-cms.com/.well-known/security.txt; both addresses are recorded there as Canonical.
What happens next
Confirming receipt
We will get back to you within three working days and tell you that your message has arrived.
Assessing
Within ten working days we will tell you how we assess the finding and what we intend to do. This applies also if we conclude that no action is required – with reasons given.
Fixing and reporting back
Once the problem has been fixed, we will let you know. On request, we will agree with you beforehand when you can write about it.
Acknowledgements
If you wish, we will name you here – with your name or a pseudonym, exactly as you prefer. Just tell us which spelling we should use. Anyone who does not wish to be named will not be named.
We cannot offer money. We are a small consultancy and do not operate a bug bounty programme. An acknowledgement in this place and honest feedback are what we can offer.
So far no one is listed here. That is welcome to change.
What this covers
Our own domains:
about-quality.deandbout-quality.de, each with and withoutwwwrr-cms.com– likewise operated by us and in productive use, among other things for e-mail
This covers not only what is visible in the browser, but also the e-mail delivery of these domains – for example flaws in SPF, DKIM or DMARC, open relays or the possibility of spoofing senders. We take such findings just as seriously as a vulnerability on the website.
Systems belonging to our clients are not included. If you find something there and suspect a connection to us, write to us all the same – we will establish the contact.
What is not a finding for us
- Output from security scanners without demonstrable impact
- Missing recommended headers, as long as nothing can be exploited as a result
- Weaknesses that only take effect in browsers that are no longer maintained
- Reports about the mere existence of a file or a directory
If in doubt: report it anyway. We will then work out together where it belongs.