Reporting security vulnerabilities

This is a translation provided for convenience. The German version at https://www.about-quality.de/security/ is the legally binding text.

We welcome every report of a vulnerability. Anyone who alerts us to a problem does us a favour – and our clients too.

Among other things, we advise companies on information security in accordance with ISO/IEC 27001. It would hardly do for us of all people to fend off such reports.

What we promise you

If you search for a vulnerability in good faith and report it to us, we will not file a criminal complaint and will not initiate civil proceedings. That is the norm, not the exception.

This promise applies as long as you keep to the points in the next section.

Two limitations that we should state openly. First: we can only speak for ourselves. If a finding concerns the systems of our hosting provider or of a client, their own rules apply there. Second: a promise from us does not override any law. It is no substitute for legal advice.

What we ask of you

How to reach us

E-mail to all@bout-quality.de. Please include:

In German or English, either is fine. If you would like to write in encrypted form, just let us know – we will then arrange the route with you.

These details are also available in machine-readable form in the security.txt in accordance with RFC 9116 – identical in wording at rr-cms.com/.well-known/security.txt; both addresses are recorded there as Canonical.

What happens next

  1. Confirming receipt

    We will get back to you within three working days and tell you that your message has arrived.

  2. Assessing

    Within ten working days we will tell you how we assess the finding and what we intend to do. This applies also if we conclude that no action is required – with reasons given.

  3. Fixing and reporting back

    Once the problem has been fixed, we will let you know. On request, we will agree with you beforehand when you can write about it.

Acknowledgements

If you wish, we will name you here – with your name or a pseudonym, exactly as you prefer. Just tell us which spelling we should use. Anyone who does not wish to be named will not be named.

We cannot offer money. We are a small consultancy and do not operate a bug bounty programme. An acknowledgement in this place and honest feedback are what we can offer.

So far no one is listed here. That is welcome to change.

What this covers

Our own domains:

This covers not only what is visible in the browser, but also the e-mail delivery of these domains – for example flaws in SPF, DKIM or DMARC, open relays or the possibility of spoofing senders. We take such findings just as seriously as a vulnerability on the website.

Systems belonging to our clients are not included. If you find something there and suspect a connection to us, write to us all the same – we will establish the contact.

What is not a finding for us

If in doubt: report it anyway. We will then work out together where it belongs.