Report a vulnerability
We take reports of vulnerabilities in our own systems seriously and handle them according to the principle of coordinated disclosure. This page describes how to reach us and what you can expect from us.
Scope
This policy applies to systems operated by TSB Top Sec Bau GmbH – in particular the website tsbsec.de and the associated e-mail infrastructure. Systems of our customers are explicitly excluded; we test those only with written authorisation.
How to report a vulnerability
Write to info@tsbsec.de. Please encrypt confidential details with our PGP key (see below). Helpful information: affected system, type of vulnerability, steps to reproduce and – if available – a proof of concept.
A machine-readable version of this information is available at /.well-known/security.txt (RFC 9116).
What we commit to
- Acknowledgement within three working days
- A dedicated contact and regular status updates
- Remediation of confirmed vulnerabilities as quickly as possible, usually within 90 days
- Public credit on request once the vulnerability is fixed
- No legal action against security researchers who follow this policy
Rules for security researchers
- Test only as far as necessary to demonstrate the vulnerability. Do not access third-party data, do not modify or delete anything.
- No denial-of-service attacks, no spam, no social engineering against our staff, no physical attacks.
- Give us time to fix the issue before publishing details – we agree on the timing together.
- Treat any data obtained incidentally as confidential and delete it after reporting.
Out of scope
- Output of automated scanners without demonstrated impact
- Missing security headers without a concrete attack scenario, clickjacking on pages without sensitive actions
- Version disclosure and best-practice deviations without exploitability
- Vulnerabilities at our hosting provider – we are happy to forward these
Rewards
We do not run a bug bounty programme. For reproducible, previously unknown vulnerabilities we say thank you – and credit you as the finder on request.
PGP key
A PGP key is currently being set up. Until then, please send confidential details by e-mail only after a short coordination with us.